Medium severity6.0NVD Advisory· Published Oct 16, 2017· Updated May 13, 2026
CVE-2017-15289
CVE-2017-15289
Description
The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- www.openwall.com/lists/oss-security/2017/10/12/16nvdMailing ListPatchThird Party Advisory
- lists.gnu.org/archive/html/qemu-devel/2017-10/msg02557.htmlnvdMailing ListPatchThird Party Advisory
- www.securityfocus.com/bid/101262nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:3368nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3369nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3466nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3470nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3471nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3472nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3473nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3474nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:0516nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlnvdThird Party Advisory
- usn.ubuntu.com/3575-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4213nvdThird Party Advisory
News mentions
0No linked articles in our index yet.