First published: Thu Oct 12 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/qemu | <=1:2.1+dfsg-12<=1:2.10.0+dfsg-2 | |
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u12 1:9.2.0+ds-2 1:9.2.0+ds-5 | |
QEMU KVM | <=2.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15289 is classified as a high-severity vulnerability due to its potential to allow privileged users to crash the QEMU process.
To fix CVE-2017-15289, upgrade to QEMU versions 1:5.2+dfsg-11+deb11u3 or higher.
CVE-2017-15289 affects QEMU versions up to and including 2.10.2.
CVE-2017-15289 is an out-of-bounds write access vulnerability related to the Cirrus CLGD 54xx VGA Emulator.
A privileged user within a guest system can exploit CVE-2017-15289 to trigger a crash in the QEMU process.