CVE-2017-15268

Public on 2017-10-12
Modified on 2018-06-11
Description
A memory leakage issue was found in the I/O channels websockets implementation of the Quick Emulator (QEMU). It could occur while sending screen updates to a client, which is slow to read and process them further. A privileged guest user could use this flaw to cause a denial of service on the host and/or potentially crash the QEMU process instance on the host.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 qemu-kvm 2018-06-08 ALAS-2018-1034 Fixed
Amazon Linux 2 - Core qemu-kvm 2018-06-07 ALAS2-2018-1034 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 2.1 AV:N/AC:H/Au:S/C:N/I:N/A:P
Amazon Linux CVSSv3 3.0 CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L
NVD CVSSv2 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P
NVD CVSSv3 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H