Data handling in QEMU - CVE-2017-10664
Published: April 30, 2018 / Updated: May 7, 2018
Vulnerability identifier: #VU12301
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10664
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system..
The weakness exists in qemu-nbd due to it does not ignore SIGPIPE. A remote attacker can cause the service to crash by disconnecting during a server-to-client reply attempt.
The weakness exists in qemu-nbd due to it does not ignore SIGPIPE. A remote attacker can cause the service to crash by disconnecting during a server-to-client reply attempt.
Affected software
QEMU
Red Hat OpenStack
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
qemu-kvm-rhev (Red Hat package)
Red Hat OpenStack
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
qemu-kvm-rhev (Red Hat package)
How to mitigate CVE-2017-10664
Install update from vendor's website.
qemu-kvm-rhev (Red Hat package) - update to 2.9.0-16.el7_4.11