CVE-2017-15124
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.8%
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.
Affected products
QEMU · QemuReferences
https://access.redhat.com/errata/RHSA-2018:0816https://access.redhat.com/errata/RHSA-2018:1104https://access.redhat.com/errata/RHSA-2018:1113https://access.redhat.com/errata/RHSA-2018:3062https://bugzilla.redhat.com/show_bug.cgi?id=1525195https://usn.ubuntu.com/3575-1/https://www.debian.org/security/2018/dsa-4213http://www.securityfocus.com/bid/102295