Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian DSA-3925-1 Critical: QEMU Denial Of Service and Buffer Overflow

debian
Calendar Grey August 4, 2017
Debian Logo
Ubuntu's USN-4653-2 provides essential patches for libxml2 tackling several security issues and potential exploits.
Multiple vulnerabilities were found in qemu, a fast processor emulator: CVE-2017-9524

Summary

Multiple vulnerabilities were found in qemu, a fast processor emulator:

CVE-2017-9524

Denial of service in qemu-nbd server

CVE-2017-10806

Buffer overflow in USB redirector

CVE-2017-11334

Out-of-band memory access in DMA operations

CVE-2017-11443

Out-of-band memory access in SLIRP/DHCP

For the stable distribution (stretch), these problems have been fixed in
version 1:2.8+dfsg-6+deb9u2.

We recommend that you upgrade your qemu packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: qemu
CVE ID: CVE-2017-9524 CVE-2017-10806 CVE-2017-11334

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here