Vulnerability CVE-2017-10664: Information

Description

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 2, 2017
Modified: Aug. 4, 2021

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
[qemu-devel] 20170611 [PATCH] qemu-nbd: Ignore SIGPIPE
  • Mailing List
  • Patch
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1466190
  • Issue Tracking
  • Patch
  • Third Party Advisory
99513
  • Third Party Advisory
  • VDB Entry
[oss-security] 20170629 CVE-2017-10664 Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort
  • Mailing List
  • Patch
  • Third Party Advisory
DSA-3920
  • Third Party Advisory
RHSA-2017:3474
  • Third Party Advisory
RHSA-2017:3473
  • Third Party Advisory
RHSA-2017:3472
  • Third Party Advisory
RHSA-2017:3471
  • Third Party Advisory
RHSA-2017:3470
  • Third Party Advisory
RHSA-2017:3466
  • Third Party Advisory
RHSA-2017:2445
  • Third Party Advisory
RHSA-2017:2390
  • Third Party Advisory
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update
  • Mailing List
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
      End including
      2.9.1

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:redhat:virtualization:3.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:redhat:openstack:7.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:6.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*