CVE-2017-18043
published 2018-01-31CVE-2017-18043: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
PriorityP416medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.44%
36.2th percentile
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.10.0+dfsg-2 (bookworm) | qemu 1:2.10.0+dfsg-2 (bookworm) |
| qemu | qemu | >= 0 < 1:2.10.0+dfsg-2 | 1:2.10.0+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.10.0+dfsg-2 | 1:2.10.0+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.10.0+dfsg-2 | 1:2.10.0+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.10.0+dfsg-2 | 1:2.10.0+dfsg-2 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.39 | 2.0.0+dfsg-2ubuntu1.39 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.40 | 2.0.0+dfsg-2ubuntu1.40 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.22 | 1:2.5+dfsg-5ubuntu10.22 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.24 | 1:2.5+dfsg-5ubuntu10.24 |
| qemu | qemu | 1.5.0 – 2.10.1 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-74x7-8qq7-46q7: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash)
ghsa_unreviewed·2022-05-14
CVE-2017-18043 [MEDIUM] CWE-190 GHSA-74x7-8qq7-46q7: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash)
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
OSV
qemu regression
osv·2018-03-05·CVSS 4.4
CVE-2017-11334 [MEDIUM] qemu regression
qemu regression
USN-3575-1 fixed vulnerabilities in QEMU. The fix for CVE-2017-11334 caused
a regression in Xen environments. This update removes the problematic fix
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discove
OSV
qemu vulnerabilities
osv·2018-02-20·CVSS 4.4
CVE-2017-11334 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the host. In the default
installation, when QEMU is used with libvir
OSV
CVE-2017-18043: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash)
osv·2018-01-31·CVSS 5.5
CVE-2017-18043 [MEDIUM] CVE-2017-18043: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash)
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Ubuntu
QEMU regression
vendor_ubuntu·2018-03-05·CVSS 4.4
CVE-2017-11334 [MEDIUM] QEMU regression
Title: QEMU regression
Summary: USN-3575-1 introduced a regression in QEMU.
USN-3575-1 fixed vulnerabilities in QEMU. The fix for CVE-2017-11334 caused
a regression in Xen environments. This update removes the problematic fix
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addres
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2018-02-20·CVSS 4.4
CVE-2017-11334 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the hos
Red Hat
Qemu: integer overflow in ROUND_UP macro could result in DoS
vendor_redhat·2017-09-14·CVSS 5.5
CVE-2017-18043 [MEDIUM] CWE-190 Qemu: integer overflow in ROUND_UP macro could result in DoS
Qemu: integer overflow in ROUND_UP macro could result in DoS
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Will not fix
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Will not fix
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Will not fix
Package: qemu-kvm (Red Hat Enterprise Linux 8) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Will not fix
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: qemu-kvm-rhev (Red Hat OpenStac
Debian
CVE-2017-18043: qemu - Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a ...
vendor_debian·2017·CVSS 5.5
CVE-2017-18043 [MEDIUM] CVE-2017-18043: qemu - Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a ...
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Scope: local
bookworm: resolved (fixed in 1:2.10.0+dfsg-2)
bullseye: resolved (fixed in 1:2.10.0+dfsg-2)
forky: resolved (fixed in 1:2.10.0+dfsg-2)
sid: resolved (fixed in 1:2.10.0+dfsg-2)
trixie: resolved (fixed in 1:2.10.0+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18043 xen: Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
bugzilla·2018-01-19·CVSS 5.5
CVE-2017-18043 [MEDIUM] CVE-2017-18043 xen: Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
CVE-2017-18043 xen: Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS
bugzilla·2018-01-19·CVSS 5.5
CVE-2017-18043 [MEDIUM] CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS
CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS
Quick Emulator(Qemu) built with a macro ROUND_UP(n, d),
used to promote number 'n' to the nearest multiple of 'd',
is vulnerable to an integer overflow issue. It could occur
if 'd' is unsigned and differs in type from 'n'.
A user/process could use this flaw to crash the Qemu process
resulting in DoS.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commit;h=2098b073f398cd628c09c5a78537a6854
Reference:
-> http://www.openwall.com/lists/oss-security/2018/01/19/1
Discussion:
Acknowledgments:
Name: Eric Blake (Red Hat Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1536380]
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1536379]
Bugzilla
CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
bugzilla·2018-01-19·CVSS 5.5
CVE-2017-18043 [MEDIUM] CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://www.openwall.com/lists/oss-security/2018/01/19/1http://www.securityfocus.com/bid/102759https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=2098b073f398cd628c09c5a78537a6854https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://usn.ubuntu.com/3575-1/https://www.debian.org/security/2018/dsa-4213http://www.openwall.com/lists/oss-security/2018/01/19/1http://www.securityfocus.com/bid/102759https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=2098b073f398cd628c09c5a78537a6854https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://usn.ubuntu.com/3575-1/https://www.debian.org/security/2018/dsa-4213
2018-01-31
Published