{"id":"CVE-2017-2630","details":"A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.","modified":"2026-08-18T10:02:05.271471Z","published":"2018-07-27T18:29:00.923Z","related":["openSUSE-SU-2024:11287-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96265"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2392"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201704-01"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1422415"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/02/15/2"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2630"},{"type":"FIX","url":"https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg01246.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"0"},{"fixed":"359c41abe32638adad503e386969fa428cecff52"},{"fixed":"2563c9c6b8670400c48e562034b321a7cf3d9a85"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.9"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.9.0-rc5","v2.9.0-rc4","v2.9.0-rc3","v2.9.0-rc2","v2.9.0-rc1","v2.8.0","v2.9.0-rc0","v2.8.0-rc4","v2.8.0-rc3","v2.8.0-rc2","v2.8.0-rc1","v2.8.0-rc0","v2.7.0","v2.7.0-rc5","v2.7.0-rc4","v2.7.0-rc3","v2.7.0-rc2","v2.6.0","v2.7.0-rc1","v2.7.0-rc0","v2.6.0-rc5","v2.6.0-rc4","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","v2.6.0-rc0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v2.4.0","v2.4.0-rc4","v2.4.0-rc3","v2.3.0","v2.4.0-rc2","v2.4.0-rc1","v2.4.0-rc0","v2.3.0-rc4","v2.3.0-rc3","v2.3.0-rc2","v2.3.0-rc1","v2.3.0-rc0","v2.2.0","v2.2.0-rc3","v2.2.0-rc5","v2.2.0-rc4","v2.2.0-rc2","v2.2.0-rc1","v2.2.0-rc0","v2.1.0","v2.1.0-rc5","v2.1.0-rc4","v2.1.0-rc2","v2.1.0-rc3","v2.0.0","v2.1.0-rc1","v2.1.0-rc0","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","v2.0.0-rc0","v1.7.0","v1.7.0-rc2","v1.7.0-rc1","v1.7.0-rc0","v1.6.0","v1.6.0-rc3","v1.6.0-rc2","v1.6.0-rc1","v1.6.0-rc0","v1.5.0","v1.5.0-rc3","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-rc0","v1.4.0","v1.4.0-rc2","v1.4.0-rc1","v1.4.0-rc0","v1.3.0","v1.3.0-rc2","v1.3.0-rc1","v1.3.0-rc0","v1.2.0","v1.2.0-rc3","v1.2.0-rc2","v1.2.0-rc1","v1.2.0-rc0","v1.1.0","v1.1.0-rc4","v1.1.0-rc3","v1.1.0-rc2","v1.1-rc2","v1.1-rc1","v1.1-rc0","v1.0","v1.0-rc4","v1.0-rc3","v1.0-rc2","v1.0-rc1","v1.0-rc0","v0.14.0-rc0","v0.13.0-rc0","v0.12.0-rc0","v0.11.0-rc0","v0.5.0","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.0","v0.2.0","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-2630.json","vanir_signatures_modified":"2026-08-18T10:02:05Z","vanir_signatures":[{"digest":{"line_hashes":["303878532369392074912772867396911496894","325746038415631207909332803864064390119","215274320153205932345462809693870818526","42768464361217919077465512044666812105"],"threshold":0.9},"id":"CVE-2017-2630-2093bbec","signature_type":"Line","signature_version":"v1","source":"https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85","target":{"file":"nbd/client.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"214583055359652706753535634819928354474","length":434},"id":"CVE-2017-2630-46aea861","signature_type":"Function","signature_version":"v1","source":"https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85","target":{"file":"nbd/client.c","function":"drop_sync"}}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/qemu-project/qemu","events":[{"introduced":"0"},{"fixed":"359c41abe32638adad503e386969fa428cecff52"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.9"}],"source":"CPE_RANGE"}}],"versions":["v2.9.0-rc5","v2.9.0-rc4","v2.9.0-rc3","v2.9.0-rc2","v2.9.0-rc1","v2.8.0","v2.9.0-rc0","v2.8.0-rc4","v2.8.0-rc3","v2.8.0-rc2","v2.8.0-rc1","v2.8.0-rc0","v2.7.0","v2.7.0-rc5","v2.7.0-rc4","v2.7.0-rc3","v2.7.0-rc2","v2.6.0","v2.7.0-rc1","v2.7.0-rc0","v2.6.0-rc5","v2.6.0-rc4","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","v2.6.0-rc0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v2.4.0","v2.4.0-rc4","v2.4.0-rc3","v2.3.0","v2.4.0-rc2","v2.4.0-rc1","v2.4.0-rc0","v2.3.0-rc4","v2.3.0-rc3","v2.3.0-rc2","v2.3.0-rc1","v2.3.0-rc0","v2.2.0","v2.2.0-rc3","v2.2.0-rc5","v2.2.0-rc4","v2.2.0-rc2","v2.2.0-rc1","v2.2.0-rc0","v2.1.0","v2.1.0-rc5","v2.1.0-rc4","v2.1.0-rc2","v2.1.0-rc3","v2.0.0","v2.1.0-rc1","v2.1.0-rc0","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","v2.0.0-rc0","v1.7.0","v1.7.0-rc2","v1.7.0-rc1","v1.7.0-rc0","v1.6.0","v1.6.0-rc3","v1.6.0-rc2","v1.6.0-rc1","v1.6.0-rc0","v1.5.0","v1.5.0-rc3","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-rc0","v1.4.0","v1.4.0-rc2","v1.4.0-rc1","v1.4.0-rc0","v1.3.0","v1.3.0-rc2","v1.3.0-rc1","v1.3.0-rc0","v1.2.0","v1.2.0-rc3","v1.2.0-rc2","v1.2.0-rc1","v1.2.0-rc0","v1.1.0","v1.1.0-rc4","v1.1.0-rc3","v1.1.0-rc2","v1.1-rc2","v1.1-rc1","v1.1-rc0","v1.0","v1.0-rc4","v1.0-rc3","v1.0-rc2","v1.0-rc1","v1.0-rc0","v0.14.0-rc0","v0.13.0-rc0","v0.12.0-rc0","v0.11.0-rc0","v0.5.0","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.0","v0.2.0","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-2630.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}