CVE-2017-15119: High severity Qemu Qemu vulnerability
Last updated 25 August 2025
Other sources
Quick Emulator(Qemu) built with the Network Block Device(NBD) server support is vulnerable to a denial-of-service issue. It could occur if a client sent large option requests, making server waste CPU time on reading up to 4G bytes.
A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-11/msg05044.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/11/28/9
— Red Hat
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qemuto a version that resolves this vulnerability.Fixed in 2.11 - Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u5Fixed in 1:7.2+dfsg-7+deb12u18Fixed in 1:7.2+dfsg-7+deb12u15Fixed in 1:10.0.11+ds-0+deb13u1Fixed in 1:10.0.2+ds-2+deb13u1Fixed in 1:11.0.2+ds-2 - Upgrade
Upgrade
QEMU (Quick Emulator) with NBD server supportto a version that resolves this vulnerability.Fixed in 2.11
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15119?
CVE-2017-15119 is classified as a denial-of-service vulnerability that can severely impact system performance.
How do I fix CVE-2017-15119?
To mitigate CVE-2017-15119, update the QEMU package to a version that is not affected, specifically 2.11 or later.
Which versions of QEMU are affected by CVE-2017-15119?
CVE-2017-15119 affects versions of QEMU prior to 2.11, as well as certain specific versions in Debian and Red Hat.
Can CVE-2017-15119 be exploited remotely?
Yes, CVE-2017-15119 can be exploited remotely if an attacker sends large option requests to the vulnerable QEMU NBD server.
What systems are vulnerable to CVE-2017-15119?
Systems using affected versions of QEMU, particularly Red Hat and Debian distributions, are vulnerable to CVE-2017-15119.