CVE Vulnerabilities

CVE-2017-9503

NULL Pointer Dereference

Published: Jun 16, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
3.4 LOW
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu*2.9.1 (including)
QemuUbuntuesm-infra-legacy/trusty*
QemuUbuntuesm-infra/xenial*
QemuUbuntutrusty*
QemuUbuntutrusty/esm*
QemuUbuntuxenial*
QemuUbuntuyakkety*
QemuUbuntuzesty*
Qemu-kvmUbuntuprecise/esm*

Potential Mitigations

References