CVE-2017-9375: Medium severity Qemu Qemu vulnerability
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
— Launchpad
Quick emulator(Qemu) built with the USB xHCI controller emulator support is vulnerable to an infinite recursive call loop issue. It could occur while processing control transfer descriptors' sequence in xhcikickepctx.
A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=96d87bdda3919bb16f754b3d3fd1227e1f38f13c
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/06/05/2
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-9375.
What is the severity of CVE-2017-9375?
The severity of CVE-2017-9375 is low.
How does CVE-2017-9375 impact QEMU?
CVE-2017-9375 allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
What software is affected by CVE-2017-9375?
QEMU versions 2.0.0+dfsg-2ubuntu1.35, 1:2.5+dfsg-5ubuntu10.15, 1:2.8+dfsg-3ubuntu2.4, and other specific versions are affected by CVE-2017-9375.
How can I fix CVE-2017-9375?
To fix CVE-2017-9375, update QEMU to the recommended versions: 2.0.0+dfsg-2ubuntu1.35, 1:2.5+dfsg-5ubuntu10.15, 1:2.8+dfsg-3ubuntu2.4, or the latest available version.