CVE-2017-9374: Medium severity Qemu Qemu vulnerability
Last updated 24 July 2024
Other sources
Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.
— Launchpad
Quick Emulator(Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while hotunplugging the device, as it does not release the memory allocated at initialisation.
A guest user/process could use this issue to leak host memory, resulting in DoS for host.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=d710e1e7bd3d5bfc26b631f02ae87901ebe646b0
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/06/06/3
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-9374.
What is the title of this vulnerability?
The title of this vulnerability is 'Memory leak in QEMU (aka Quick Emulator) when built with USB EHCI Emulation support allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.'
What is the severity level of CVE-2017-9374?
The severity level of CVE-2017-9374 is low.
How does CVE-2017-9374 affect the software?
CVE-2017-9374 affects the software QEMU when built with USB EHCI Emulation support.
How can CVE-2017-9374 be fixed?
CVE-2017-9374 can be fixed by applying the recommended patches provided by the software vendor.