CVE-2017-9373

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device.

References

http://git.qemu.org/?p=qemu.git;a=commit;h=d68f0f778e7f4fbd674627274267f269e40f0b04

http://www.debian.org/security/2017/dsa-3920

http://www.openwall.com/lists/oss-security/2017/06/05/1

http://www.securityfocus.com/bid/98921

https://access.redhat.com/errata/RHSA-2017:2392

https://access.redhat.com/errata/RHSA-2017:2408

https://bugzilla.redhat.com/show_bug.cgi?id=1458270

https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html

Details

Source: MITRE

Published: 2017-06-16

Updated: 2020-11-10

Type: CWE-401

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
135559EulerOS 2.0 SP3 : qemu-kvm (EulerOS-SA-2020-1430)NessusHuawei Local Security Checks
critical
131585EulerOS 2.0 SP2 : qemu-kvm (EulerOS-SA-2019-2431)NessusHuawei Local Security Checks
critical
130689EulerOS 2.0 SP5 : qemu-kvm (EulerOS-SA-2019-2227)NessusHuawei Local Security Checks
critical
124947EulerOS Virtualization 3.0.1.0 : qemu (EulerOS-SA-2019-1444)NessusHuawei Local Security Checks
high
124908EulerOS Virtualization for ARM 64 3.0.1.0 : qemu-kvm (EulerOS-SA-2019-1405)NessusHuawei Local Security Checks
high
117351Debian DLA-1497-1 : qemu security update (Spectre)NessusDebian Local Security Checks
critical
104780SUSE SLES11 Security Update : kvm (SUSE-SU-2017:3084-1)NessusSuSE Local Security Checks
critical
104495SUSE SLES12 Security Update : qemu (SUSE-SU-2017:2969-1)NessusSuSE Local Security Checks
critical
104494SUSE SLES11 Security Update : kvm (SUSE-SU-2017:2963-1)NessusSuSE Local Security Checks
critical
104471SUSE SLES12 Security Update : qemu (SUSE-SU-2017:2946-1)NessusSuSE Local Security Checks
critical
103372Ubuntu 14.04 LTS / 16.04 LTS / 17.04 : qemu regression (USN-3414-2)NessusUbuntu Local Security Checks
critical
103217Ubuntu 14.04 LTS / 16.04 LTS / 17.04 : qemu vulnerabilities (USN-3414-1)NessusUbuntu Local Security Checks
critical
102158RHEL 7 : qemu-kvm-rhev (RHSA-2017:2392)NessusRed Hat Local Security Checks
high
101985Debian DSA-3920-1 : qemu - security updateNessusDebian Local Security Checks
high
101758openSUSE Security Update : qemu (openSUSE-2017-822)NessusSuSE Local Security Checks
critical
101227SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2017:1774-1)NessusSuSE Local Security Checks
critical