ALT-PU-2017-2765-1
Closed vulnerabilities
Published: 2017-12-01
BDU:2019-04122
Уязвимость компонента Virtio Vring эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (6.5)
Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity: MEDIUM (4.6)
Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C
References:
Published: 2017-12-07
Modified: 2025-04-20
Modified: 2025-04-20
CVE-2017-17381
The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.
Severity: LOW (2.1)
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
References:
- http://www.openwall.com/lists/oss-security/2017/12/05/2
- http://www.securityfocus.com/bid/102059
- https://lists.gnu.org/archive/html/qemu-devel/2017-12/msg00166.html
- https://usn.ubuntu.com/3575-1/
- https://www.debian.org/security/2018/dsa-4213
- http://www.openwall.com/lists/oss-security/2017/12/05/2
- http://www.securityfocus.com/bid/102059
- https://lists.gnu.org/archive/html/qemu-devel/2017-12/msg00166.html
- https://usn.ubuntu.com/3575-1/
- https://www.debian.org/security/2018/dsa-4213