Your submission was sent successfully! Close

CVE-2017-9524

Published: 6 July 2017

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Not vulnerable
(code not present)
upstream Needed

xenial Not vulnerable
(code not present)
yakkety Ignored
(reached end-of-life)
zesty
Released (1:2.8+dfsg-3ubuntu2.4)
Patches:
upstream: https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=df8ad9f128c15aa0a0ebc7b24e9a22c9775b67af
upstream: https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=0c9390d978cbf61e8f16c9f580fa96b305c43568
qemu-kvm
Launchpad, Ubuntu, Debian
precise Not vulnerable
(code not present)
trusty Does not exist

upstream Needed

xenial Does not exist

yakkety Does not exist

zesty Does not exist