First published: Wed Mar 15 2017(Updated: )
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.8.1.1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5525 is classified as a denial of service vulnerability affecting QEMU.
CVE-2017-5525 can lead to host memory consumption and crashes of the QEMU process due to memory leaks.
CVE-2017-5525 affects QEMU versions prior to 2.8.1.1.
To mitigate CVE-2017-5525, upgrading to QEMU version 2.8.1.1 or later is recommended.
Local guest OS privileged users can exploit CVE-2017-5525 on systems running susceptible versions of QEMU.