Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-15268

Published: 12 October 2017

Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.

Priority

Low

CVSS 3 base score: 7.5

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
artful
Released (1:2.10+dfsg-0ubuntu3.5)
precise Does not exist

trusty Not vulnerable
(code not present)
upstream Needs triage

xenial Not vulnerable
(code not present)
zesty Ignored
(reached end-of-life)
Patches:
upstream: https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=a7b20a8efa28e5f22c26c06cd06c2f12bc863493
qemu-kvm
Launchpad, Ubuntu, Debian
artful Does not exist

precise Not vulnerable
(code not present)
trusty Does not exist

upstream Needs triage

xenial Does not exist

zesty Does not exist