CVE-2017-6505Infinite Loop in Qemu

CWE-835Infinite Loop16 documents7 sources
Severity
6.5MEDIUMNVD
NVD5.6OSV5.5
EPSS
0.1%
top 69.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateMay 13

Description

The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors, a different vulnerability than CVE-2017-9330.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages4 packages

debiandebian/qemu< qemu 1:2.8+dfsg-7 (bookworm)+1
Debianqemu/qemu< 1:2.8+dfsg-4+7
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.33+1
NVDqemu/qemu2.8.1.1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-pfx6-rwwf-8mgx: The ohci_service_ed_list function in hw/usb/hcd-ohci2022-05-13
GHSA
GHSA-fxf9-ppj6-ph5r: QEMU (aka Quick Emulator) before 22022-05-13
OSV
CVE-2017-9330: QEMU (aka Quick Emulator) before 22017-06-08
OSV
qemu vulnerabilities2017-04-20
OSV
CVE-2017-6505: The ohci_service_ed_list function in hw/usb/hcd-ohci2017-03-15

📋Vendor Advisories

6
Ubuntu
QEMU vulnerabilities2017-04-25
Ubuntu
QEMU vulnerabilities2017-04-20
Red Hat
Qemu: usb: ohci: infinite loop due to incorrect return value2017-02-07
Red Hat
Qemu: usb: an infinite loop issue in ohci_service_ed_list2017-02-07
Debian
CVE-2017-9330: qemu - QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation s...2017

💬Community

3
Bugzilla
CVE-2017-6505 xen: Qemu: usb: an infinite loop issue in ohci_service_ed_list [fedora-all]2017-03-06
Bugzilla
CVE-2017-6505 Qemu: usb: an infinite loop issue in ohci_service_ed_list [fedora-all]2017-03-06
Bugzilla
CVE-2017-6505 Qemu: usb: an infinite loop issue in ohci_service_ed_list2017-03-06