CVE-2017-13711: Debian Linux

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Qemu Qemu: up to and including 2.10.1

Published 2017-09-01. Last modified 2026-06-17.