CVE-2017-9503: Null Pointer Dereference
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
— Launchpad
Quick Emulator(Qemu) built with the MegaRAID SAS 8708EM2 Host Bus Adapter emulation support is vulnerable to a null pointer dereference issue. It could occur while processing megasas commands via megasascommandcomplete().
A privileged user inside guest could use this flaw to crash the Qemu process on the host resulting in DoS.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg01313.html -> https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg01309.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/06/08/1
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2017-9503?
The vulnerability severity of CVE-2017-9503 is low.
How does CVE-2017-9503 affect QEMU?
CVE-2017-9503 affects QEMU when it is built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support.
Who is affected by CVE-2017-9503?
Local guest OS privileged users are affected by CVE-2017-9503.
What is the impact of CVE-2017-9503?
The impact of CVE-2017-9503 is a denial of service (NULL pointer dereference and QEMU process crash).
How can I fix CVE-2017-9503?
To fix CVE-2017-9503, it is recommended to update QEMU to the specified patched versions provided by the respective distributions.