The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.
References
Configurations
History
No history.
Information
Published : 2017-04-10 15:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-7377
Mitre link : CVE-2017-7377
CVE.ORG link : CVE-2017-7377
JSON object : View
Products Affected
qemu
- qemu
debian
- debian_linux
CWE
CWE-772
Missing Release of Resource after Effective Lifetime