CVE-2017-2630
published 2018-07-27CVE-2017-2630: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur…
PriorityP356high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.65%
83.9th percentile
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.8+dfsg-3 (bookworm) | qemu 1:2.8+dfsg-3 (bookworm) |
| qemu | qemu | < 2.9 | 2.9 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2rf9-cmpf-qww5: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2
ghsa_unreviewed·2022-05-13
CVE-2017-2630 [HIGH] CWE-121 GHSA-2rf9-cmpf-qww5: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
OSV
CVE-2017-2630: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2
osv·2018-07-27·CVSS 8.8
CVE-2017-2630 [HIGH] CVE-2017-2630: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
Red Hat
Qemu: nbd: oob stack write in client routine drop_sync
vendor_redhat·2017-02-03·CVSS 5.5
CVE-2017-2630 [MEDIUM] CWE-121 Qemu: nbd: oob stack write in client routine drop_sync
Qemu: nbd: oob stack write in client routine drop_sync
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on
Debian
CVE-2017-2630: qemu - A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 b...
vendor_debian·2017·CVSS 5.5
CVE-2017-2630 [MEDIUM] CVE-2017-2630: qemu - A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 b...
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed in 1:2.8+dfsg-3)
forky: resolved (fixed in 1:2.8+dfsg-3)
sid: resolved (fixed in 1:2.8+dfsg-3)
trixie: resolved (fixed in 1:2.8+dfsg-3)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2017/02/15/2http://www.securityfocus.com/bid/96265https://access.redhat.com/errata/RHSA-2017:2392https://bugzilla.redhat.com/show_bug.cgi?id=1422415https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2630https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg01246.htmlhttps://security.gentoo.org/glsa/201704-01http://www.openwall.com/lists/oss-security/2017/02/15/2http://www.securityfocus.com/bid/96265https://access.redhat.com/errata/RHSA-2017:2392https://bugzilla.redhat.com/show_bug.cgi?id=1422415https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2630https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg01246.htmlhttps://security.gentoo.org/glsa/201704-01
2018-07-27
Published