cbcvebase.
CVE-2017-15119
published 2018-07-27

CVE-2017-15119: The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large…

high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianqemu< qemu 1:2.11+dfsg-1 (bookworm)qemu 1:2.11+dfsg-1 (bookworm)
qemuqemu< 2.11.02.11.0
qemuqemu
qemuqemu>= 0 < 1:2.11+dfsg-11:2.11+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-11:2.11+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-11:2.11+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-11:2.11+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.392.0.0+dfsg-2ubuntu1.39
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.402.0.0+dfsg-2ubuntu1.40
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.221:2.5+dfsg-5ubuntu10.22
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.241:2.5+dfsg-5ubuntu10.24
redhatvirtualization

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
osv8.6HIGH