CVE-2017-10806: Buffer Overflow
Last updated 24 July 2024
Other sources
Quick emulator(Qemu) built with the USB redirector support is vulnerable to a stack buffer overflow flaw. It could occur while logging debug messages when the debug mode is enabled in the device.
A user/process could use this flaw to crash the Qemu process on the host resulting in DoS.
Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2017-05/msg03087.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/07/07/1
— Red Hat
Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-10806?
CVE-2017-10806 is a vulnerability in QEMU (Quick Emulator) that allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
How does CVE-2017-10806 affect QEMU?
CVE-2017-10806 affects QEMU by creating a stack-based buffer overflow in the redirect.c file of the QEMU software.
How can I fix the CVE-2017-10806 vulnerability on Ubuntu trusty?
To fix the CVE-2017-10806 vulnerability on Ubuntu trusty, update your QEMU package to version 2.0.0+dfsg-2ubuntu1.35 or higher.
How can I fix the CVE-2017-10806 vulnerability on Ubuntu xenial?
To fix the CVE-2017-10806 vulnerability on Ubuntu xenial, update your QEMU package to version 1:2.5+dfsg-5ubuntu10.15 or higher.
Is the severity of CVE-2017-10806 low?
Yes, the severity of CVE-2017-10806 is low.