VulnerabilityModified
CVE-2017-8379
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
MEDIUM 6.5EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-772
- Affected
- qemu/qemu · debian/debian linux · redhat/openstack
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/05/03/2Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98277Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2408Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg05599.htmlMailing List, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201706-03Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/05/03/2Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98277Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2408Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg05599.htmlMailing List, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201706-03Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.