CVE-2017-5579: Medium severity Qemu Qemu vulnerability
Memory leak in the serialexitcore function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Other sources
Quick Emulator(Qemu) built with the 16550A UART serial device emulation support is vulnerable to a memory leakage issue. It could occur while doing a device unplug operation; Doing so repeatedly would result in leaking host memory, affecting other services on the host.
A privileged user inside guest could use this flaw to cause a DoS and/or potentially crash the Qemu process on the host.
Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg01945.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5579?
CVE-2017-5579 is considered a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2017-5579?
To fix CVE-2017-5579, you should upgrade QEMU to the latest version that addresses this memory leak issue.
Who is affected by CVE-2017-5579?
CVE-2017-5579 affects local guest OS privileged users running vulnerable versions of QEMU.
What are the main impacts of CVE-2017-5579?
The main impacts of CVE-2017-5579 are host memory consumption and potential crashes of the QEMU process.
Which versions of QEMU are vulnerable to CVE-2017-5579?
Versions of QEMU from 2.8.1.1 up to 2.9.0-rc5 are vulnerable to CVE-2017-5579.