CVE-2017-5578: Medium severity Qemu Qemu vulnerability
Memory leak in the virtiogpuresourceattachbacking function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIOGPUCMDRESOURCEATTACHBACKING commands.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5578?
CVE-2017-5578 is classified as a denial of service vulnerability that can lead to significant memory consumption on the host.
How do I fix CVE-2017-5578?
To mitigate CVE-2017-5578, you should upgrade to the latest version of QEMU beyond 2.8.1.1 where the vulnerability has been patched.
What systems are affected by CVE-2017-5578?
CVE-2017-5578 affects QEMU versions up to and including 2.8.1.1.
What is the main impact of exploiting CVE-2017-5578?
Exploiting CVE-2017-5578 can lead to a denial of service by exhausting host memory through excessive VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
Who can exploit CVE-2017-5578?
CVE-2017-5578 can be exploited by local users of a guest operating system running on an affected QEMU instance.