CVE-2017-11334
published 2017-08-02CVE-2017-11334: The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.50%
40.0th percentile
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.8+dfsg-7 (bookworm) | qemu 1:2.8+dfsg-7 (bookworm) |
| qemu | qemu | <= 2.9.1 | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.39 | 2.0.0+dfsg-2ubuntu1.39 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.40 | 2.0.0+dfsg-2ubuntu1.40 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.22 | 1:2.5+dfsg-5ubuntu10.22 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.24 | 1:2.5+dfsg-5ubuntu10.24 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU regression
vendor_ubuntu·2018-03-05·CVSS 4.4
CVE-2017-11334 [MEDIUM] QEMU regression
Title: QEMU regression
Summary: USN-3575-1 introduced a regression in QEMU.
USN-3575-1 fixed vulnerabilities in QEMU. The fix for CVE-2017-11334 caused
a regression in Xen environments. This update removes the problematic fix
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addres
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2018-02-20·CVSS 4.4
CVE-2017-11334 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the hos
Red Hat
Qemu: exec: oob access during dma operation
vendor_redhat·2017-07-13·CVSS 4.4
CVE-2017-11334 [MEDIUM] CWE-787 Qemu: exec: oob access during dma operation
Qemu: exec: oob access during dma operation
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
Quick Emulator (QEMU), compiled with qemu_map_ram_ptr to access guests' RAM block area, is vulnerable to an OOB r/w access issue. The crash can occur if a privileged user inside a guest conducts certain DMA operations, resulting in a DoS.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2017-11334: qemu - The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator)...
vendor_debian·2017·CVSS 4.4
CVE-2017-11334 [MEDIUM] CVE-2017-11334: qemu - The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator)...
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-7)
bullseye: resolved (fixed in 1:2.8+dfsg-7)
forky: resolved (fixed in 1:2.8+dfsg-7)
sid: resolved (fixed in 1:2.8+dfsg-7)
trixie: resolved (fixed in 1:2.8+dfsg-7)
GHSA
GHSA-4j6c-x59q-c2c4: The address_space_write_continue function in exec
ghsa_unreviewed·2022-05-13
CVE-2017-11334 [MEDIUM] CWE-125 GHSA-4j6c-x59q-c2c4: The address_space_write_continue function in exec
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
OSV
qemu regression
osv·2018-03-05·CVSS 4.4
CVE-2017-11334 [MEDIUM] qemu regression
qemu regression
USN-3575-1 fixed vulnerabilities in QEMU. The fix for CVE-2017-11334 caused
a regression in Xen environments. This update removes the problematic fix
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discove
OSV
qemu vulnerabilities
osv·2018-02-20·CVSS 4.4
CVE-2017-11334 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the host. In the default
installation, when QEMU is used with libvir
OSV
CVE-2017-11334: The address_space_write_continue function in exec
osv·2017-08-02·CVSS 4.4
CVE-2017-11334 [MEDIUM] CVE-2017-11334: The address_space_write_continue function in exec
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11334 Qemu: exec: oob access during dma operation
bugzilla·2017-07-17·CVSS 4.4
CVE-2017-11334 [MEDIUM] CVE-2017-11334 Qemu: exec: oob access during dma operation
CVE-2017-11334 Qemu: exec: oob access during dma operation
Qemu emulator built to use 'qemu_map_ram_ptr' to access guests' ram block area
is vulnerable to a OOB r/w access issue. It could occur during a DMA operation.
A privileged user inside guest could use this flaw to crash the guest instance
resulting in DoS.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=04bf2526ce87f21b32c9acba1c5518708c243ad0
Reference:
-> http://www.openwall.com/lists/oss-security/2017/07/17/4
Discussion:
Acknowledgments:
Name: Alex
---
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1471640]
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1471639]
---
This issue has been addressed in the following products:
RHEV 4.X RHEV-H and Agents fo
Bugzilla
CVE-2017-11334 xen: Qemu: exec: oob access during dma operation [fedora-all]
bugzilla·2017-07-17·CVSS 4.4
CVE-2017-11334 [MEDIUM] CVE-2017-11334 xen: Qemu: exec: oob access during dma operation [fedora-all]
CVE-2017-11334 xen: Qemu: exec: oob access during dma operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2017-11334 Qemu: exec: oob access during dma operation [fedora-all]
bugzilla·2017-07-17·CVSS 4.4
CVE-2017-11334 [MEDIUM] CVE-2017-11334 Qemu: exec: oob access during dma operation [fedora-all]
CVE-2017-11334 Qemu: exec: oob access during dma operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
http://www.debian.org/security/2017/dsa-3925http://www.openwall.com/lists/oss-security/2017/07/17/4http://www.securityfocus.com/bid/99895https://access.redhat.com/errata/RHSA-2017:3369https://access.redhat.com/errata/RHSA-2017:3466https://access.redhat.com/errata/RHSA-2017:3470https://access.redhat.com/errata/RHSA-2017:3471https://access.redhat.com/errata/RHSA-2017:3472https://access.redhat.com/errata/RHSA-2017:3473https://access.redhat.com/errata/RHSA-2017:3474https://bugzilla.redhat.com/show_bug.cgi?id=1471638https://lists.gnu.org/archive/html/qemu-devel/2017-07/msg03775.htmlhttps://usn.ubuntu.com/3575-1/http://www.debian.org/security/2017/dsa-3925http://www.openwall.com/lists/oss-security/2017/07/17/4http://www.securityfocus.com/bid/99895https://access.redhat.com/errata/RHSA-2017:3369https://access.redhat.com/errata/RHSA-2017:3466https://access.redhat.com/errata/RHSA-2017:3470https://access.redhat.com/errata/RHSA-2017:3471https://access.redhat.com/errata/RHSA-2017:3472https://access.redhat.com/errata/RHSA-2017:3473https://access.redhat.com/errata/RHSA-2017:3474https://bugzilla.redhat.com/show_bug.cgi?id=1471638https://lists.gnu.org/archive/html/qemu-devel/2017-07/msg03775.htmlhttps://usn.ubuntu.com/3575-1/
2017-08-02
Published