Memory corruption in QEMU - CVE-2017-14167
Published: April 30, 2018
Vulnerability identifier: #VU12300
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14167
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.
The weakness exists in the load_multiboot function in hw/i386/multiboot.c due to integer overflow. An adjacent attacker can execute arbitrary code via specially crafted multiboot header address values, which trigger an out-of-bounds write.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the load_multiboot function in hw/i386/multiboot.c due to integer overflow. An adjacent attacker can execute arbitrary code via specially crafted multiboot header address values, which trigger an out-of-bounds write.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
QEMU
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Virtualization
Red Hat OpenStack
qemu-kvm-rhev (Red Hat package)
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Virtualization
Red Hat OpenStack
qemu-kvm-rhev (Red Hat package)
How to mitigate CVE-2017-14167
Install update from vendor's website.
qemu-kvm-rhev (Red Hat package) - update to 2.9.0-16.el7_4.11
External References
Related Security Bulletins
- Amazon Linux AMI update for qemu-kvm
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm
- Red Hat Enterprise Linux OpenStack Platform 6 update for qemu-kvm-rhev