CVE-2017-9524: Input Validation
Last updated 24 July 2024
Other sources
Quick Emulator(Qemu) built with the Network Block Device(NBD) Server support is vulnerable to a null pointer dereference issue. It could occur while releasing a client, which was not initialised due to failed negotiation.
A remote user/process could use this flaw to crash the qemu-nbd server resulting in DoS.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-05/msg06240.html -> https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg02321.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/06/12/1
— Red Hat
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbdnegotiate function.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-9524.
What is the severity level of CVE-2017-9524?
The severity level of CVE-2017-9524 is medium.
How does the vulnerability in CVE-2017-9524 affect the qemu-nbd server in QEMU?
The vulnerability in CVE-2017-9524 allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the qemu-nbd server in QEMU.
What are the affected software versions for CVE-2017-9524?
The affected software versions for CVE-2017-9524 include qemu 1:2.8+dfsg-3ubuntu2.4 in Ubuntu, and qemu 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u10, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u1, 1:8.0.4+dfsg-3, and 1:8.1.0+ds-6 in Debian.
Are there any remedies available for the affected software versions of CVE-2017-9524?
Yes, there are remedies available for the affected software versions of CVE-2017-9524. For Ubuntu, the remedy is qemu 1:2.8+dfsg-3ubuntu2.4. For Debian, the remedies include qemu 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u10, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u1, 1:8.0.4+dfsg-3, and 1:8.1.0+ds-6.