CVE-2017-8380Improper Restriction of Operations within the Bounds of a Memory Buffer in Qemu

Severity
9.8CRITICALNVD
OSV7.8
EPSS
2.8%
top 13.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28
Latest updateMay 17

Description

Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/qemu< qemu 1:2.8+dfsg-5 (bookworm)
Debianqemu/qemu< 1:2.8+dfsg-5+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.36+3
NVDqemu/qemu2.9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4xjw-56mf-3pfv: Buffer overflow in the "megasas_mmio_write" function in Qemu 22022-05-17
OSV
qemu regression2017-09-20
OSV
qemu vulnerabilities2017-09-13
OSV
CVE-2017-8380: Buffer overflow in the "megasas_mmio_write" function in Qemu 22017-08-28

💥Exploits & PoCs

1
Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting2017-01-07

📋Vendor Advisories

4
Ubuntu
QEMU regression2017-09-20
Ubuntu
QEMU vulnerabilities2017-09-13
Red Hat
Qemu: scsi: megasas: out-of-bounds read in megasas_mmio_write2017-04-24
Debian
CVE-2017-8380: qemu - Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote...2017

💬Community

2
Bugzilla
CVE-2017-8380 Qemu: scsi: megasas: out-of-bounds read in megasas_mmio_write2017-04-28
Bugzilla
CVE-2017-8380 Qemu: scsi: megasas: out-of-bounds read in megasas_mmio_write [fedora-all]2017-04-28