cbcvebase.
CVE-2017-2620
published 2018-07-27

CVE-2017-2620: Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur…

PriorityP261critical9.9CVSS 3.0
AVNACLPRLUINSCCHIHAH
EPSS
3.56%
88.1th percentile
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debianqemu< qemu 1:2.8+dfsg-3 (bookworm)qemu 1:2.8+dfsg-3 (bookworm)
debianxen< qemu 1:2.8+dfsg-3 (bookworm)qemu 1:2.8+dfsg-3 (bookworm)
qemuqemu< 2.8.02.8.0
qemuqemu
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.332.0.0+dfsg-2ubuntu1.33
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.111:2.5+dfsg-5ubuntu10.11
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop

Detection & IOCsextracted from sources · hover to see the quote

processcirrus_bitblt_cputovideo
  • The fix adds a `blit_is_unsafe` call to `cirrus_bitblt_cputovideo`; absence of this check in the Cirrus CLGD 54xx VGA emulator code path indicates a vulnerable QEMU version.
  • Exploitation requires a privileged (e.g., root) user inside the guest VM targeting the Cirrus CLGD 54xx VGA emulator; monitor for unexpected QEMU process crashes or privilege escalation on the host originating from guest VGA operations.
  • Upstream patch available at the qemu-devel mailing list; use this to confirm patch application status on monitored systems.
  • ·Vulnerability only affects QEMU instances built with Cirrus CLGD 54xx VGA Emulator support; deployments using other VGA emulator backends are not affected.
  • ·Red Hat OpenStack Platform 11 (Ocata) ships a version of qemu-kvm-rhev that is not affected; verify the specific package version before applying mitigations.
  • ·The xen package on Red Hat Enterprise Linux 5 will not be fixed; operators relying on Xen on RHEL 5 should consider alternative mitigations such as disabling the Cirrus VGA device.

CVSS provenance

nvdv3.09.9CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.9CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.