CVE-2017-8379Missing Release of Resource after Effective Lifetime in Qemu

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 65.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 13

Description

Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages3 packages

Debianqemu/qemu< 1:2.8+dfsg-5+3
NVDqemu/qemu2.9.1
NVDredhat/openstack6 versions+5

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rr9p-xg7r-p8xg: Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of serv2022-05-13
OSV
CVE-2017-8379: Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of serv2017-05-23
CVEList
CVE-2017-8379: Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of serv2017-05-23

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2017-05-16
Red Hat
Qemu: input: host memory lekage via keyboard events2017-04-28
Debian
CVE-2017-8379: qemu - Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emul...2017

💬Community

3
Bugzilla
CVE-2017-8379 Qemu: input: host memory lekage via keyboard events [fedora-all]2017-04-28
Bugzilla
CVE-2017-8379 Qemu: input: host memory lekage via keyboard events2017-04-28
Bugzilla
CVE-2017-8379 xen: Qemu: input: host memory lekage via keyboard events [fedora-all]2017-04-28
CVE-2017-8379 — Qemu vulnerability | cvebase