The Network Block Device (NBD) server in Quick Emulator (QEMU)...
Vulnerability Description
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15119
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.gnu.org/archive/html/qemu-devel/2017-11/msg05044.html
- http://www.openwall.com/lists/oss-security/2017/11/28/9
- http://www.securityfocus.com/bid/102011
- https://www.debian.org/security/2018/dsa-4213
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15119
- https://access.redhat.com/errata/RHSA-2018:1104
- https://access.redhat.com/errata/RHSA-2018:1113
- https://usn.ubuntu.com/3575-1/
More from QEMU
View All →Affected Vendor
QEMU
View all reports →