Описание
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
A use-after-free issue was found in the Slirp networking implementation of the Quick emulator (QEMU). It occurs when a Socket referenced from multiple packets is freed while responding to a message. A user/process could use this flaw to crash the QEMU process on the host resulting in denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kvm | Will not fix | ||
Red Hat Enterprise Linux 5 | xen | Not affected | ||
Red Hat Enterprise Linux 6 | qemu-kvm | Affected | ||
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux 7 | qemu-kvm | Fixed | RHSA-2018:0816 | 10.04.2018 |
Red Hat OpenStack Platform 10.0 (Newton) | qemu-kvm-rhev | Fixed | RHSA-2018:1113 | 11.04.2018 |
Red Hat OpenStack Platform 11.0 (Ocata) | qemu-kvm-rhev | Fixed | RHSA-2018:1113 | 11.04.2018 |
Red Hat OpenStack Platform 12.0 (Pike) | qemu-kvm-rhev | Fixed | RHSA-2018:1113 | 11.04.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.4 Low
CVSS3
2.9 Low
CVSS2
Связанные уязвимости
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
Use-after-free vulnerability in the sofree function in slirp/socket.c ...
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
ELSA-2018-0816: qemu-kvm security, bug fix, and enhancement update (LOW)
EPSS
3.4 Low
CVSS3
2.9 Low
CVSS2