CVE-2017-2620
published 2018-07-27CVE-2017-2620: Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur…
PriorityP261critical9.9CVSS 3.0
AVNACLPRLUINSCCHIHAH
EPSS
3.56%
88.1th percentile
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.8+dfsg-3 (bookworm) | qemu 1:2.8+dfsg-3 (bookworm) |
| debian | xen | < qemu 1:2.8+dfsg-3 (bookworm) | qemu 1:2.8+dfsg-3 (bookworm) |
| qemu | qemu | < 2.8.0 | 2.8.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.33 | 2.0.0+dfsg-2ubuntu1.33 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.11 | 1:2.5+dfsg-5ubuntu10.11 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The fix adds a `blit_is_unsafe` call to `cirrus_bitblt_cputovideo`; absence of this check in the Cirrus CLGD 54xx VGA emulator code path indicates a vulnerable QEMU version. ↗
- →Exploitation requires a privileged (e.g., root) user inside the guest VM targeting the Cirrus CLGD 54xx VGA emulator; monitor for unexpected QEMU process crashes or privilege escalation on the host originating from guest VGA operations. ↗
- →Upstream patch available at the qemu-devel mailing list; use this to confirm patch application status on monitored systems. ↗
- ·Vulnerability only affects QEMU instances built with Cirrus CLGD 54xx VGA Emulator support; deployments using other VGA emulator backends are not affected. ↗
- ·Red Hat OpenStack Platform 11 (Ocata) ships a version of qemu-kvm-rhev that is not affected; verify the specific package version before applying mitigations. ↗
- ·The xen package on Red Hat Enterprise Linux 5 will not be fixed; operators relying on Xen on RHEL 5 should consider alternative mitigations such as disabling the Cirrus VGA device. ↗
CVSS provenance
nvdv3.09.9CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.9CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ub
Red Hat
Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
vendor_redhat·2017-02-21·CVSS 5.5
CVE-2017-2620 [MEDIUM] CWE-787 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the
Debian
CVE-2017-2620: qemu - Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator su...
vendor_debian·2017·CVSS 5.5
CVE-2017-2620 [MEDIUM] CVE-2017-2620: qemu - Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator su...
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed in 1:2.8+dfsg-3)
forky: resolved (fixed in 1:2.8+dfsg-3)
sid: resolved (fixed in 1:2.8+dfsg-3)
trixie: resolved (fixed in 1:2.8+dfsg-3)
Citrix
Citrix Security Bulletin CTX220771
vendor_citrix·CVSS 9.1
CVE-2017-2615 [CRITICAL] Citrix Security Bulletin CTX220771
Citrix Security Bulletin CTX220771
CVE References: CVE-2017-2615, CVE-2017-2620, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-v6gr-ph59-9hqm: Quick emulator (QEMU) before 2
ghsa_unreviewed·2022-05-13
CVE-2017-2620 [CRITICAL] CWE-125 GHSA-v6gr-ph59-9hqm: Quick emulator (QEMU) before 2
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
OSV
CVE-2017-2620: Quick emulator (QEMU) before 2
osv·2018-07-27·CVSS 9.9
CVE-2017-2620 [CRITICAL] CVE-2017-2620: Quick emulator (QEMU) before 2
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
OSV
qemu vulnerabilities
osv·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)
It was disc
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
bugzilla·2017-02-21·CVSS 5.5
CVE-2017-2620 [MEDIUM] CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2017-2620 xen: Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
bugzilla·2017-02-21·CVSS 5.5
CVE-2017-2620 [MEDIUM] CVE-2017-2620 xen: Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
CVE-2017-2620 xen: Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
bugzilla·2017-02-08·CVSS 5.5
CVE-2017-2620 [MEDIUM] CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
CVE-2017-2620 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
Quick emulator(Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is
vulnerable to an out-of-bounds access issue. It could occur while copying
VGA data in cirrus_bitblt_cputovideo.
A privileged user inside guest could use this flaw to crash the Qemu process
resulting in DoS OR potentially execute arbitrary code on the host with
privileges of Qemu process on the host.
Upstream patch
-> https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg04700.html
Reference:
-> http://www.openwall.com/lists/oss-security/2017/02/21/1
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1425420]
---
Created qemu tracking bugs for this issue:
Affects: fedora-all
Bugzilla
CVE-2016-10092 libtiff: Heap-based buffer overflow in _TIFFFax3fillruns
bugzilla·2017-01-04·CVSS 7.8
CVE-2016-10092 [HIGH] CVE-2016-10092 libtiff: Heap-based buffer overflow in _TIFFFax3fillruns
CVE-2016-10092 libtiff: Heap-based buffer overflow in _TIFFFax3fillruns
An out-of-bounds heap write was found in _TIFFFax3fillruns when output buffer was not correctly incremented in readContigStripsIntoBuffer() in ignore mode in tiffcrop.c
Upstream patch:
https://github.com/vadz/libtiff/commit/9657bbe3cdce4aaa90e07d50c1c70ae52da0ba6a
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2620
CVE assignment:
http://seclists.org/oss-sec/2017/q1/9
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1410123]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1410124]
Affects: epel-7 [bug 1410125]
http://rhn.redhat.com/errata/RHSA-2017-0328.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0329.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0330.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0331.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0332.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0333.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0334.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0350.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0351.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0352.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0396.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0454.htmlhttp://www.openwall.com/lists/oss-security/2017/02/21/1http://www.securityfocus.com/bid/96378http://www.securitytracker.com/id/1037870https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2620https://lists.debian.org/debian-lts-announce/2018/02/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2017-02/msg04700.htmlhttps://security.gentoo.org/glsa/201703-07https://security.gentoo.org/glsa/201704-01https://support.citrix.com/article/CTX220771https://xenbits.xen.org/xsa/advisory-209.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0328.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0329.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0330.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0331.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0332.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0333.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0334.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0350.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0351.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0352.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0396.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0454.htmlhttp://www.openwall.com/lists/oss-security/2017/02/21/1http://www.securityfocus.com/bid/96378http://www.securitytracker.com/id/1037870https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2620https://lists.debian.org/debian-lts-announce/2018/02/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2017-02/msg04700.htmlhttps://security.gentoo.org/glsa/201703-07https://security.gentoo.org/glsa/201704-01https://support.citrix.com/article/CTX220771https://xenbits.xen.org/xsa/advisory-209.html
2018-07-27
Published