peter bassill · operator
$ cve CVE-2017-15118 JSON

CVE-2017-15118 EXPLOIT

8.3
HIGH · CVSS 3.0 · EPSS 11.9% (pctl 96)

Patch early

A public exploit exists.

Description

A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.

Scoring

CVSS8.3 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS11.93% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploityes
Published2018-07-27
Last modified2026-06-17

Affected (3)

VendorProduct
canonicalubuntu linux
qemuqemu
redhatenterprise linux

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD