CVE-2017-8086: Medium severity Qemu Qemu vulnerability
Memory leak in the v9fslistxattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the origvalue variable.
Other sources
Quick Emulator(Qemu) built with the virtio-9p back-end support is vulnerable to a memory leakage issue. It could occur while querying file system extended attributes via 9pfslistxattr() routine.
A privileged user/process inside guest could use this flaw to leak host memory resulting in Dos.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=4ffcdef4277a91af15a3c09f7d16af072c29f3f2
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/04/25/5
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8086?
CVE-2017-8086 has been classified with a moderate severity as it can lead to a denial of service due to memory consumption.
How do I fix CVE-2017-8086?
To address CVE-2017-8086, you should upgrade QEMU to version 2.9.0 or later to eliminate the memory leak vulnerability.
Who is affected by CVE-2017-8086?
CVE-2017-8086 affects local guest OS privileged users running specific versions of QEMU built with the virtio-9p back-end support.
What is the cause of CVE-2017-8086?
CVE-2017-8086 is caused by a memory leak in the v9fs_list_xattr function within the QEMU codebase.
What versions of QEMU are vulnerable to CVE-2017-8086?
Versions of QEMU up to 2.8.1 and 2.9.0-rc0, 2.9.0-rc1, 2.9.0-rc2, and 2.9.0-rc3 are vulnerable to CVE-2017-8086.