CVE-2017-6058
published 2017-03-20CVE-2017-6058: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.92%
89.2th percentile
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.8+dfsg-3 (bookworm) | qemu 1:2.8+dfsg-3 (bookworm) |
| qemu | qemu | <= 2.8.1.1 | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-3 | 1:2.8+dfsg-3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat9.8CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: use-after-free in flash
vendor_redhat·2018-03-06·CVSS 9.8
CVE-2018-6058 [CRITICAL] chromium-browser: use-after-free in flash
chromium-browser: use-after-free in flash
[REJECTED CVE] An use after free flaw was found in the Flash component of the Chromium browser.
Statement: This flaw was found to be a duplicate of CVE-2017-11215. Please see https://access.redhat.com/security/cve/CVE-2017-11215 for information about affected products and security errata.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
vendor_redhat·2017-02-16·CVSS 7.5
CVE-2017-6058 [HIGH] CWE-120 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: qemu-kvm-rhev (
Debian
CVE-2017-6058: qemu - Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick ...
vendor_debian·2017·CVSS 7.5
CVE-2017-6058 [HIGH] CVE-2017-6058: qemu - Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick ...
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed in 1:2.8+dfsg-3)
forky: resolved (fixed in 1:2.8+dfsg-3)
sid: resolved (fixed in 1:2.8+dfsg-3)
trixie: resolved (fixed in 1:2.8+dfsg-3)
GHSA
GHSA-3wcr-p8pv-4w4w: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt
ghsa_unreviewed·2022-05-13
CVE-2017-6058 [HIGH] CWE-120 GHSA-3wcr-p8pv-4w4w: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
OSV
CVE-2017-6058: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt
osv·2017-03-20·CVSS 7.5
CVE-2017-6058 [HIGH] CVE-2017-6058: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6058 chromium-browser: use-after-free in flash
bugzilla·2018-03-07·CVSS 9.8
CVE-2018-6058 [CRITICAL] CVE-2018-6058 chromium-browser: use-after-free in flash
CVE-2018-6058 chromium-browser: use-after-free in flash
An use after free flaw was found in the Flash component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758848
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
The Google blog post referenced in comment 0 was updated and no longer mentions this CVE. It now lists different CVE for this issue instead:
[$5000][758848] High CVE-2017-11215: Use after free in Flash. Reported by JieZeng of Tencent Zhanlu Lab on 2017-08-25
The CVE-2017-11215 is for Adobe Flash Player and it was previously covered by Adobe
Bugzilla
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
bugzilla·2017-02-17·CVSS 7.5
CVE-2017-6058 [HIGH] CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping
Quick Emulator(Qemu) built with the VMWARE VMXNET3 NIC device support
is vulnerable to an out-of-bounds access issue. It could occur while
stripping VLAN header from 'eth_buf' buffer in receiving packets.
A remote user/process could use this issue to crash Qemu process instance
resulting in DoS.
Note:- It requires 'VLANSTRIP' feature is enabled on the vmxnet3 device.
Upstream patch:
-> https://lists.nongnu.org/archive/html/qemu-devel/2017-02/msg03527.html
Reference:
-> http://www.openwall.com/lists/oss-security/2017/02/17/2
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1423359]
Bugzilla
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping [fedora-all]
bugzilla·2017-02-17·CVSS 7.5
CVE-2017-6058 [HIGH] CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping [fedora-all]
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
http://git.qemu-project.org/?p=qemu.git%3Ba=commit%3Bh=df8bf7a7fe75eb5d5caffa55f5cd4292b757aea6http://www.openwall.com/lists/oss-security/2017/02/17/2http://www.securityfocus.com/bid/96277http://www.securitytracker.com/id/1037856https://bugzilla.redhat.com/show_bug.cgi?id=1423358https://lists.nongnu.org/archive/html/qemu-devel/2017-02/msg03527.htmlhttps://security.gentoo.org/glsa/201704-01http://git.qemu-project.org/?p=qemu.git%3Ba=commit%3Bh=df8bf7a7fe75eb5d5caffa55f5cd4292b757aea6http://www.openwall.com/lists/oss-security/2017/02/17/2http://www.securityfocus.com/bid/96277http://www.securitytracker.com/id/1037856https://bugzilla.redhat.com/show_bug.cgi?id=1423358https://lists.nongnu.org/archive/html/qemu-devel/2017-02/msg03527.htmlhttps://security.gentoo.org/glsa/201704-01
2017-03-20
Published