cbcvebase.
CVE-2017-10664
published 2017-08-02

CVE-2017-10664: qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.8+dfsg-7 (bookworm)qemu 1:2.8+dfsg-7 (bookworm)
qemuqemu<= 2.9.1
qemuqemu>= 0 < 1:2.8+dfsg-71:2.8+dfsg-7
qemuqemu>= 0 < 1:2.8+dfsg-71:2.8+dfsg-7
qemuqemu>= 0 < 1:2.8+dfsg-71:2.8+dfsg-7
qemuqemu>= 0 < 1:2.8+dfsg-71:2.8+dfsg-7
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.362.0.0+dfsg-2ubuntu1.36
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.352.0.0+dfsg-2ubuntu1.35
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.161:2.5+dfsg-5ubuntu10.16
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.151:2.5+dfsg-5ubuntu10.15
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH