CVE-2017-8112: Medium severity Qemu Qemu vulnerability
hw/scsi/vmwpvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
Other sources
Quick Emulator(Qemu) built with the VMWARE PVSCSI paravirtual SCSI bus emulation support is vulnerable to an infinite loop issue. It could occur while initialising SCSI message ring buffer in pvscsilog2().
A privileged user inside guest could use this flaw to consume host cpu cycles or crash the Qemu process resulting in DoS.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg04578.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/04/26/5
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8112?
The severity of CVE-2017-8112 is low.
How does CVE-2017-8112 impact QEMU?
CVE-2017-8112 allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
Which versions of QEMU are affected by CVE-2017-8112?
Versions 2.0.0+dfsg-2ubuntu1.35 and lower, 1:2.5+dfsg-5ubuntu10.15 and lower, 1:2.8+dfsg-3ubuntu2.4 and lower, and 1:3.1+dfsg-8+deb10u8 and lower are affected by CVE-2017-8112.
How can I fix the vulnerability in QEMU?
To fix the vulnerability in QEMU, update to version 2.0.0+dfsg-2ubuntu1.35 or above for Ubuntu, version 1:2.5+dfsg-5ubuntu10.15 or above for Xenial, version 1:2.8+dfsg-3ubuntu2.4 or above for Zesty, or one of the specified versions for Debian.
Where can I find more information about CVE-2017-8112?
You can find more information about CVE-2017-8112 at the following references: [1] [2] [3].