CVE-2017-9310: Medium severity Qemu Qemu vulnerability
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer.
Qemu emulator built with the e1000e NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head(TDH/RDH) is set outside the allocated descriptor buffer.
A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4154c7e03fa55b4cf52509a83d50d6c09d743b7
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/05/31/1
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2017-9310?
CVE-2017-9310 is a vulnerability in QEMU (aka Quick Emulator) that allows local guest OS privileged users to cause a denial of service (infinite loop) by setting the initial receive/transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer.
What is the severity of CVE-2017-9310?
The severity of CVE-2017-9310 is low.
How can I fix CVE-2017-9310?
To fix CVE-2017-9310, update QEMU to version 1:2.8+dfsg-3ubuntu2.4 (for Ubuntu), 10:2.9.0-10.el7 or 10:2.9.0-14.el7 (for Red Hat), and 1:3.1+dfsg-8+deb10u8 or later (for Debian).
Where can I find more information about CVE-2017-9310?
You can find more information about CVE-2017-9310 in the references section: [1](http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4154c7e03fa55b4cf52509a83d50d6c09d743b7), [2](http://www.openwall.com/lists/oss-security/2017/05/31/1), [3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1452623).