Memory leak in QEMU - CVE-2017-15268

 

Memory leak in QEMU - CVE-2017-15268

Published: April 16, 2018 / Updated: April 25, 2018


Vulnerability identifier: #VU12163
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15268
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoІ condition on the target system.

The weakness exists in io/channel-websock.c due to memory leak in slow data-channel read operations. A remote attacker can trigger memory corruption and cause the service to crash.


Affected software

QEMU
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
qemu

How to mitigate CVE-2017-15268

Update to version 2.10.1.

qemu - update to 2.10.1-1.fc27

External References

Related Security Bulletins