CVE-2017-2630
Summary
| CVE | CVE-2017-2630 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 18:29:00 UTC |
| Updated | 2023-11-07 02:43:00 UTC |
| Description | A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process. |
Risk And Classification
Problem Types: CWE-121
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Re: [Qemu-devel] [PATCH 05/18] nbd/client: fix drop_sync | MLIST | lists.gnu.org | Patch, Third Party Advisory |
| QEMU 'nbd/client.c' Stack Buffer Overflow Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - CVE-2017-2630 Qemu: nbd: oob stack write in client routine drop_sync | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| 1422415 – (CVE-2017-2630) CVE-2017-2630 Qemu: nbd: oob stack write in client routine drop_sync | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| nbd/client: fix drop_sync [CVE-2017-2630] · qemu/qemu@2563c9c · GitHub | MISC | github.com | |
| QEMU: Multiple vulnerabilities (GLSA 201704-01) — Gentoo Security | GENTOO | security.gentoo.org | Third Party Advisory |
| Bug 1422415 – CVE-2017-2630 Qemu: nbd: oob stack write in client routine drop_sync | CONFIRM | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710523 Gentoo Linux QEMU Multiple Vulnerabilities (GLSA 201704-01)