CVE-2017-2633: Qemu

Medium severity, CVSS 6.5. EPSS: 3% chance of exploitation in the next 30 days.

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.

Affected products

  • Qemu Qemu: before 1.7.2 (fixed in 1.7.2)
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only
  • Red Hat Enterprise Linux Server Eus: version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2018-07-27. Last modified 2026-06-17.