CVE-2017-15118 is a critical stack-based buffer overflow vulnerability affecting QEMU versions prior to 2.11, specifically within its NBD server implementation. This flaw allows a malicious NBD client to send an excessively long export name, exceeding the intended 256-byte limit and causing an out-of-bounds write in the QEMU process. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. If TLS is enforced, an attacker must first successfully negotiate TLS. While not listed on the CISA KEV catalog and showing no community discussion or media coverage, a public exploit (EDB-43194) exists, indicating the potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.