Back to search
CVE-2017-13711
Published: Sep 1, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
100534
vdb-entry
x_refsource_BID
RHSA-2018:0816
vendor-advisory
x_refsource_REDHAT
[oss-security] 20170829 CVE-2017-13711 Qemu: Slirp: use-after-free when sending response
mailing-list
x_refsource_MLIST
DSA-3991
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:1104
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1113
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1486400
x_refsource_CONFIRM
[qemu-devel] 20170826 [PATCH] slirp: fix clearing ifq_so from pending packets
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now