CVE-2017-9524Improper Input Validation in Qemu

Severity
7.5HIGHNVD
OSV7.8
EPSS
2.1%
top 15.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 6
Latest updateMay 13

Description

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/qemu< qemu 1:2.8+dfsg-7 (bookworm)
Debianqemu/qemu< 1:2.8+dfsg-7+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.36+3
NVDqemu/qemu2.9.1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3hp7-3fxw-3v9g: The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a de2022-05-13
OSV
qemu regression2017-09-20
OSV
qemu vulnerabilities2017-09-13
OSV
CVE-2017-9524: The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a de2017-07-06

📋Vendor Advisories

4
Ubuntu
QEMU regression2017-09-20
Ubuntu
QEMU vulnerabilities2017-09-13
Red Hat
Qemu: nbd: segmentation fault due to client non-negotiation2017-05-26
Debian
CVE-2017-9524: qemu - The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Bl...2017

💬Community

3
Bugzilla
CVE-2017-9524 Qemu: nbd: segmentation fault due to client non-negotiation2017-06-09
Bugzilla
CVE-2017-9524 xen: Qemu: nbd: segmentation fault due to client non-negotiation [fedora-all]2017-06-09
Bugzilla
CVE-2017-9524 Qemu: nbd: segmentation fault due to client non-negotiation [fedora-all]2017-06-09