CVE-2017-12809: Null Pointer Dereference
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-12809?
CVE-2017-12809 is a vulnerability in QEMU (aka Quick Emulator) that allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
What software is affected by CVE-2017-12809?
QEMU versions 1:2.5+dfsg-5ubuntu10.15, 1:2.8+dfsg-3ubuntu2.4, 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u10, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u1, 1:8.1.0+ds-6, and 1:8.1.1+ds-1 on Ubuntu and Debian systems are affected.
What is the severity of CVE-2017-12809?
CVE-2017-12809 has a severity rating of 6.5, which is classified as medium.
How do I fix CVE-2017-12809?
To fix CVE-2017-12809, update QEMU to version 1:2.5+dfsg-5ubuntu10.15 on Ubuntu systems or version 1:2.8+dfsg-3ubuntu2.4 on Debian systems.
Where can I find more information about CVE-2017-12809?
You can find more information about CVE-2017-12809 at the following references: http://www.openwall.com/lists/oss-security/2017/08/21/2, https://lists.gnu.org/archive/html/qemu-devel/2017-08/msg01850.html, http://www.securityfocus.com/bid/100451