CVE-2017-5898: Qemu

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.

Affected products

  • Qemu Qemu: up to and including 2.8.1.1
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 12 only
  • Suse Linux Enterprise Server For SAP: version 12 only
  • Suse Linux Enterprise Software Development Kit: version 12 only

Published 2017-03-15. Last modified 2026-06-17.