CVE-2017-5525: Medium severity Qemu Qemu vulnerability
Published Mar 15, 2017
·Updated
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Affected Software
2 affected components
Qemu Qemu<=2.8.1.1
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Event History
Mar 15, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5525?
CVE-2017-5525 is classified as a denial of service vulnerability affecting QEMU.
2
How does CVE-2017-5525 impact the system?
CVE-2017-5525 can lead to host memory consumption and crashes of the QEMU process due to memory leaks.
3
What versions of QEMU are affected by CVE-2017-5525?
CVE-2017-5525 affects QEMU versions prior to 2.8.1.1.
4
How can I mitigate the effects of CVE-2017-5525?
To mitigate CVE-2017-5525, upgrading to QEMU version 2.8.1.1 or later is recommended.
5
Who is affected by CVE-2017-5525?
Local guest OS privileged users can exploit CVE-2017-5525 on systems running susceptible versions of QEMU.