Improper input validation in QEMU - CVE-2017-13673

 

Improper input validation in QEMU - CVE-2017-13673

Published: April 11, 2018 / Updated: April 13, 2018


Vulnerability identifier: #VU11818
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13673
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent authenticated attacker to cause DoS condition on the target system.

The vulnerability exists in the vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode in the cpu_physical_memory_snapshot_get_dirty function due to assertion failure. An adjacent attacker can cause the service to crash.


Affected software

QEMU
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Fedora
Opensuse
xen

How to mitigate CVE-2017-13673

Install update from vendor's website.

xen - addressed in versions 4.7.3-6.fc25, 4.7.3-7.fc25, 4.8.2-3.fc26, 4.8.2-4.fc26, 4.9.0-11.fc27

External References

Related Security Bulletins