CVE-2017-18043: Integer Overflow
Integer overflow in the macro ROUNDUP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u5Fixed in 1:7.2+dfsg-7+deb12u18Fixed in 1:7.2+dfsg-7+deb12u15Fixed in 1:10.0.11+ds-0+deb13u1Fixed in 1:10.0.2+ds-2+deb13u1Fixed in 1:11.0.2+ds-2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18043?
The severity of CVE-2017-18043 is considered high as it allows for denial of service through a crash of the Qemu process.
How do I fix CVE-2017-18043?
To fix CVE-2017-18043, update Qemu to a version that includes the mitigation or patch for the integer overflow issue.
Which versions of Qemu are affected by CVE-2017-18043?
CVE-2017-18043 affects Qemu versions between 1.5.0 and 2.10.1 inclusively.
Is CVE-2017-18043 relevant for Debian users?
Yes, Debian versions 9.0 and Qemu packages within specific version ranges are affected by CVE-2017-18043.
What operating systems are impacted by CVE-2017-18043?
CVE-2017-18043 impacts various versions of Debian GNU/Linux and Ubuntu Linux, particularly versions 14.04, 16.04, and 17.10.