CVE-2017-7539Reachable Assertion in Qemu

Severity
7.5HIGHNVD
CNA5.3
EPSS
2.8%
top 13.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected data during connection negotiation. A remote user or process could use this flaw to crash the qemu-nbd server resulting in denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDqemu/qemu< 2.10.1
CVEListV5qemu/qemu2.10.1
NVDredhat/openstack6 versions+5
NVDredhat/virtualization3.0, 4.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8vvg-hj6f-q4wj: An assertion-failure flaw was found in Qemu before 22022-05-13
CVEList
CVE-2017-7539: An assertion-failure flaw was found in Qemu before 22018-07-26

📋Vendor Advisories

2
Red Hat
Qemu: qemu-nbd crashes due to undefined I/O coroutine2017-06-02
Debian
CVE-2017-7539: qemu - An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block ...2017

💬Community

3
Bugzilla
CVE-2017-7539 Qemu: qemu-nbd crashes due to undefined I/O coroutine2017-07-21
Bugzilla
CVE-2017-7539 Qemu: qemu-nbd crashes due to undefined I/O coroutine [fedora-all]2017-07-21
Bugzilla
CVE-2017-7539 xen: Qemu: qemu-nbd crashes due to undefined I/O coroutine [fedora-all]2017-07-21
CVE-2017-7539 — Reachable Assertion in Qemu | cvebase