4.9
CVSSv2

CVE-2017-5525

Published: 15/03/2017 Updated: 12/02/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in QEMU ...
Debian Bug report logs - #851910 qemu: CVE-2017-5526 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Jan 2017 21:09:02 UTC Severity: normal Tags: patch, security, upstream Found in version qem ...
Debian Bug report logs - #852021 qemu: CVE-2017-5525 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 Jan 2017 19:09:01 UTC Severity: normal Tags: patch, security, upstream Found in version qem ...
Debian Bug report logs - #852119 qemu: CVE-2017-5552 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 21 Jan 2017 19:12:04 UTC Severity: normal Tags: fixed-upstream, patch, security, upstream Foun ...
Debian Bug report logs - #849798 qemu: CVE-2016-10028: display: virtio-gpu-3d: OOB access while reading virgl capabilities Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 31 Dec 2016 06:51:01 UTC ...
Debian Bug report logs - #852232 qemu: CVE-2016-10155 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 22 Jan 2017 18:51:01 UTC Severity: normal Tags: patch, security, upstream Found in version qe ...
Memory leak in hw/audio/ac97c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations ...