CVE-2017-7539: Input Validation

Published Jul 21, 2017
·
Updated

An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected data during connection negotiation. A remote user or process could use this flaw to crash the qemu-nbd server resulting in denial of service.

Other sources

Quick Emulator(Qemu) built with the Network Block Device(NBD) Server support is vulnerable to a crash via assertion failure. It could occur if a client sent undue data during initial connection negotiation.

A remote user/process could use this flaw to crash the qemu-nbd server resulting in DoS.

Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=2b0bbc4f8809c972bad134bc1a2570dbb01dea0b

Introduced by: -------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=ff82911cd3f69f028f2537825c9720ff78bc3f19

Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/07/21/4

Red Hat

Affected Software

10 affected components
Qemu Qemu<2.10.1
redhat Openstack=6.0
redhat Openstack=7.0
redhat Openstack=8
redhat Openstack=9
redhat Openstack=10
redhat Openstack=11
redhat Virtualization=4.0
redhat Virtualization=3.0
redhat Enterprise Linux=7.0

Event History

Jul 21, 2017
Data Sourced
via Red Hat·10:31 AM
DescriptionSeverityAffected Software
Jul 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-7539?

CVE-2017-7539 has a medium severity rating due to the potential for denial of service attacks.

2

How do I fix CVE-2017-7539?

To fix CVE-2017-7539, upgrade QEMU to version 2.10.1 or later, or apply relevant patches provided by your software vendor.

3

Which versions of QEMU are affected by CVE-2017-7539?

QEMU versions prior to 2.10.1 are affected by CVE-2017-7539.

4

Can CVE-2017-7539 be exploited remotely?

Yes, CVE-2017-7539 can be exploited remotely by sending unexpected data during connection negotiation to the qemu-nbd server.

5

What software products are impacted by CVE-2017-7539?

Software products impacted by CVE-2017-7539 include QEMU versions earlier than 2.10.1 and several versions of Red Hat OpenStack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203