CVE-2010-0297: Buffer Overflow
Buffer overflow in the usbhosthandlecontrol function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
Other sources
Description of problem: usb-linux.c: fix buffer overflow - made into 0.11.1. This bug is to ensure we backport this change to 0.10.0.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0297?
CVE-2010-0297 has a severity level that can lead to denial of service or potential remote code execution.
How do I fix CVE-2010-0297?
To fix CVE-2010-0297, upgrade QEMU to version 0.11.1 or later.
What versions of QEMU are affected by CVE-2010-0297?
CVE-2010-0297 affects QEMU versions prior to 0.11.1, including 0.1.0 to 0.11.0-rc1.
What types of attacks can exploit CVE-2010-0297?
CVE-2010-0297 can be exploited through crafted USB packets resulting in guest OS crashes or arbitrary code execution.
Who is affected by CVE-2010-0297?
Users running vulnerable versions of QEMU are at risk of CVE-2010-0297.