6.5

CVE-2017-5579

Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version <= 2.8.1.1
Qemu ≫ Qemu Version 2.9.0 Update rc0
Qemu ≫ Qemu Version 2.9.0 Update rc1
Qemu ≫ Qemu Version 2.9.0 Update rc2
Qemu ≫ Qemu Version 2.9.0 Update rc3
Qemu ≫ Qemu Version 2.9.0 Update rc4
Qemu ≫ Qemu Version 2.9.0 Update rc5
Debian ≫ Debian Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://access.redhat.com/errata/RHSA-2017:2392
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2408
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html
Third Party Advisory
https://security.gentoo.org/glsa/201702-28
Third Party Advisory
http://git.qemu-project.org/?p=qemu.git%3Ba=commit%3Bh=8409dc884a201bf74b30a9d232b6bbdd00cb7e2b
http://www.openwall.com/lists/oss-security/2017/01/24/8
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2017/01/25/3
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/95780
Third Party Advisory
VDB Entry