CVE-2017-5526: Medium severity Qemu Qemu vulnerability
Published Mar 15, 2017
·Updated
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Affected Software
2 affected components
Qemu Qemu<=2.8.1.1
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Event History
Mar 15, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5526?
CVE-2017-5526 is classified as a high-severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2017-5526?
To mitigate CVE-2017-5526, upgrade to a newer version of QEMU that is above 2.8.1.1.
3
What versions of QEMU are affected by CVE-2017-5526?
CVE-2017-5526 affects all versions of QEMU up to and including 2.8.1.1.
4
What are the consequences of exploiting CVE-2017-5526?
Exploitation of CVE-2017-5526 can lead to excessive host memory consumption and potential QEMU process crashes.
5
Who is impacted by CVE-2017-5526?
Local guest OS privileged users leveraging device unplug operations are primarily impacted by CVE-2017-5526.