Stack-based buffer overflow in QEMU - CVE-2017-15118
Published: August 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the network block device (NBD) server implementation due to stack-based buffer overflow when handling malicious input. A remote unauthenticated attacker can send a large export-name request, trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.
Affected software
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Fedora
qemu
How to mitigate CVE-2017-15118
qemu - update to 2.10.2-1.fc27