First published: Wed Feb 01 2017(Updated: )
Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.8.1.1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5856 is considered to be moderate as it can lead to denial of service through memory consumption.
To fix CVE-2017-5856, you should upgrade to a patched version of QEMU that addresses this memory leak.
CVE-2017-5856 affects local privileged users of guest operating systems running QEMU versions up to 2.8.1.1.
CVE-2017-5856 is a memory leak vulnerability that allows abuse of MegaRAID Firmware Interface commands.
CVE-2017-5856 can cause denial of service by excessive host memory consumption due to large sglist sizes.