Data handling in QEMU - CVE-2017-10664

 

Data handling in QEMU - CVE-2017-10664

Published: April 30, 2018 / Updated: May 7, 2018


Vulnerability identifier: #VU12301
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10664
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system..

The weakness exists in qemu-nbd due to it does not ignore SIGPIPE. A remote attacker can cause the service to crash by disconnecting during a server-to-client reply attempt.

Affected software

QEMU
Red Hat OpenStack
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
qemu-kvm-rhev (Red Hat package)

How to mitigate CVE-2017-10664

Install update from vendor's website.

qemu-kvm-rhev (Red Hat package) - update to 2.9.0-16.el7_4.11

External References

Related Security Bulletins