« List of all CVEs

CVE-2017-15119

Published: 7/27/2018 Last updated: 8/5/2024 Reserved: 10/8/2017

The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 5.8 Medium CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (1)

Product Vendor Version
qemu QEMU <= 5.15.*

References (16)