CVE-2017-5552: Medium severity Qemu Qemu vulnerability
Memory leak in the virglresourceattachbacking function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIOGPUCMDRESOURCEATTACHBACKING commands.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5552?
CVE-2017-5552 is classified as a high severity vulnerability due to its potential for causing denial of service through excessive memory consumption.
How do I fix CVE-2017-5552?
To mitigate CVE-2017-5552, it is recommended to upgrade QEMU to version 2.8.1.2 or later where the vulnerability has been addressed.
Who is affected by CVE-2017-5552?
Users of QEMU versions up to 2.8.1.1 are affected by CVE-2017-5552, particularly those running guest operating systems.
What is the impact of CVE-2017-5552?
The impact of CVE-2017-5552 includes potential denial of service conditions due to a memory leak from numerous VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
Is CVE-2017-5552 a local or remote vulnerability?
CVE-2017-5552 is a local vulnerability, as it requires local guest OS users to exploit the issue.