CVE-2017-6058Classic Buffer Overflow in Qemu

Severity
7.5HIGHNVD
EPSS
3.4%
top 12.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Latest updateMay 13

Description

Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/qemu< qemu 1:2.8+dfsg-3 (bookworm)
Debianqemu/qemu< 1:2.8+dfsg-3+3
NVDqemu/qemu2.8.1.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3wcr-p8pv-4w4w: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt2022-05-13
OSV
CVE-2017-6058: Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt2017-03-20

📋Vendor Advisories

3
Red Hat
chromium-browser: use-after-free in flash2018-03-06
Red Hat
Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping2017-02-16
Debian
CVE-2017-6058: qemu - Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick ...2017

💬Community

3
Bugzilla
CVE-2018-6058 chromium-browser: use-after-free in flash2018-03-07
Bugzilla
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping2017-02-17
Bugzilla
CVE-2017-6058 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping [fedora-all]2017-02-17