CVE-2017-7377: Medium severity Qemu Qemu vulnerability

Published Mar 31, 2017
·
Updated

Quick Emulator(Qemu) built with the virtio-9p back-end support is vulnerable to a memory leakage issue. It could occur while doing a I/O operation via v9fscreate/v9fslcreate routine.

A privileged user/process inside guest could use this flaw to leak host memory resulting in Dos.

Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-03/msg05449.html

Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/04/03/2

Other sources

The (1) v9fscreate and (2) v9fslcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

MITRE

Affected Software

4 affected components
Qemu Qemu<=2.8.1
Qemu Qemu=2.9.0-rc0
Qemu Qemu=2.9.0-rc1
Debian Debian Linux=8.0

Event History

Mar 31, 2017
Data Sourced
via Red Hat·11:49 AM
DescriptionSeverityAffected Software
Apr 10, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2017-7377?

CVE-2017-7377 has a high severity due to its potential to cause denial of service by leaking host memory.

2

How do I fix CVE-2017-7377?

To fix CVE-2017-7377, upgrade QEMU to a version later than 2.8.1 that includes the upstream patch.

3

Who is affected by CVE-2017-7377?

CVE-2017-7377 affects QEMU installations with virtio-9p back-end support that are running specific vulnerable versions.

4

What type of vulnerability is CVE-2017-7377?

CVE-2017-7377 is a memory leakage vulnerability occurring during I/O operations in QEMU.

5

Can unprivileged users exploit CVE-2017-7377?

No, CVE-2017-7377 can only be exploited by a privileged user or process within the guest environment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203