CVE-2017-13672: Debian Linux

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Qemu Qemu: up to and including 2.10.2

Published 2017-09-01. Last modified 2026-06-17.