Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux SE 1.5
Astra Linux SE 1.6
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:ru.altx-soft.nix:def:27464
[Eng]
Version
7
Class
patch
ALTXid
155355
Language
Russian
Severity
Critical
Title
Обновление USN-3125-1 -- уязвимости QEMU
Description
Multiple vulnerabilities in Qemu.
Family
unix
Platform
Linux Mint 17
Linux Mint 18
Ubuntu 12.04
Ubuntu 14.04
Ubuntu 16.04
Ubuntu 16.10
Product
qemu
Reference
VENDOR: USN-3125-1
VENDOR: USN-3125-1
Id:
USN-3125-1
Reference:
http://www.ubuntu.com/usn/usn-3125-1/
CVE: CVE-2016-5403
CVE: CVE-2016-5403
Id:
CVE-2016-5403
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5403
Comment
: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
http://xenbits.xen.org/xsa/advisory-184.html (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1358359 (CONFIRM)
92148 (BID)
1036476 (SECTRACK)
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html (CONFIRM)
USN-3047-1 (UBUNTU)
USN-3047-2 (UBUNTU)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html (CONFIRM)
RHSA-2016:1654 (REDHAT)
RHSA-2016:1653 (REDHAT)
RHSA-2016:1655 (REDHAT)
RHSA-2016:1652 (REDHAT)
RHSA-2016:1763 (REDHAT)
RHSA-2016:1607 (REDHAT)
RHSA-2016:1606 (REDHAT)
RHSA-2016:1756 (REDHAT)
RHSA-2016:1586 (REDHAT)
RHSA-2016:1585 (REDHAT)
RHSA-2016:1943 (REDHAT)
[debian-lts-announce] 20190920 [SECURITY] [DLA 1927-1] qemu security update (MLIST)
CVE: CVE-2016-6833
CVE: CVE-2016-6833
Id:
CVE-2016-6833
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6833
Comment
: Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
93255 (BID)
[oss-security] 20160817 Re: CVE request: Qemu net: vmxnet3: use after free while writing (MLIST)
[qemu-devel] 20160809 [PULL 2/3] net: vmxnet3: check for device_active before write (MLIST)
[oss-security] 20160812 CVE request: Qemu net: vmxnet3: use after free while writing (MLIST)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=6c352ca9b4ee3e1e286ea9e8434bd8e69ac7d0d8 (MISC)
CVE: CVE-2016-6834
CVE: CVE-2016-6834
Id:
CVE-2016-6834
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6834
Comment
: The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20160817 Re: CVE request Qemu: an infinite loop during packet fragmentation (MLIST)
[qemu-devel] 20160809 [PULL 1/3] net: check fragment length during fragmentation (MLIST)
[oss-security] 20160812 CVE request Qemu: an infinite loop during packet fragmentation (MLIST)
92446 (BID)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=ead315e43ea0c2ca3491209c6c8db8ce3f2bbe05 (MISC)
CVE: CVE-2016-6888
CVE: CVE-2016-6888
Id:
CVE-2016-6888
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6888
Comment
: Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
92556 (BID)
[oss-security] 20160819 CVE Request: Qemu: net: vmxnet: integer overflow in packet initialisation (MLIST)
[qemu-devel] 20160818 [PULL 1/2] net: vmxnet: use g_new for pkt initialisation (MLIST)
[oss-security] 20160819 Re: CVE Request: Qemu: net: vmxnet: integer overflow in packet initialisation (MLIST)
GLSA-201609-01 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=47882fa4975bf0b58dd74474329fdd7154e8f04c ()
CVE: CVE-2016-6835
CVE: CVE-2016-6835
Id:
CVE-2016-6835
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6835
Comment
: The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
[oss-security] 20160812 CVE request Qemu: buffer overflow in vmxnet_tx_pkt_parse_headers() in vmxnet3 device emulation (MLIST)
[qemu-devel] 20160810 Re: [PATCH] net: vmxnet: check IP header length (MLIST)
[oss-security] 20160817 Re: CVE request Qemu: buffer overflow in vmxnet_tx_pkt_parse_headers() in vmxnet3 device emulation (MLIST)
RHSA-2017:2392 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=93060258ae748573ca7197204125a2670047896d (MISC)
CVE: CVE-2016-6836
CVE: CVE-2016-6836
Id:
CVE-2016-6836
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6836
Comment
: The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE:
665 (Improper Initialization)
References:
[oss-security] 20160817 Re: CVE Request Qemu: Information leak in vmxnet3_complete_packet (MLIST)
[oss-security] 20160812 CVE Request Qemu: Information leak in vmxnet3_complete_packet (MLIST)
[qemu-devel] 20160811 [PATCH] net: vmxnet: initialise local tx descriptor (MLIST)
92444 (BID)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fdda170e50b8af062cf5741e12c4fb5e57a2eacf (MISC)
CVE: CVE-2016-7116
CVE: CVE-2016-7116
Id:
CVE-2016-7116
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7116
Comment
: Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE:
22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
References:
[qemu-devel] 20160826 [PATCH v2 0/5] 9P security fixes (MLIST)
[qemu-devel] 20160830 [PATCH v4 0/3] 9pfs security fixes (MLIST)
[oss-security] 20160830 CVE request: Qemu: 9p: directory traversal flaw in 9p virtio backend (MLIST)
[oss-security] 20160830 Re: CVE request: Qemu: 9p: directory traversal flaw in 9p virtio backend (MLIST)
92680 (BID)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=56f101ecce0eafd09e2daf1c4eeb1377d6959261 (MISC)
CVE: CVE-2016-7155
CVE: CVE-2016-7155
Id:
CVE-2016-7155
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7155
Comment
: hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References:
92772 (BID)
[qemu-devel] 20160901 [PATCH v3] scsi: check page count while initialising descriptor rings (MLIST)
[oss-security] 20160906 CVE request: Qemu: scsi: pvscsi: OOB read and infinite loop while setting descriptor rings (MLIST)
[oss-security] 20160906 Re: CVE request: Qemu: scsi: pvscsi: OOB read and infinite loop while setting descriptor rings (MLIST)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=7f61f4690dd153be98900a2a508b88989e692753 ()
CVE: CVE-2016-7156
CVE: CVE-2016-7156
Id:
CVE-2016-7156
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7156
Comment
: The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
704 (Incorrect Type Conversion or Cast)
References:
[oss-security] 20160906 Re: CVE request: Qemu: scsi: pvscsi: infintie loop when building SG list (MLIST)
[oss-security] 20160906 CVE request: Qemu: scsi: pvscsi: infintie loop when building SG list (MLIST)
92774 (BID)
[qemu-devel] 20160906 [PATCH v3] scsi: pvscsi: avoid infinite loop while building SG list (MLIST)
[qemu-devel] 20160906 [PATCH v2] scsi: pvscsi: check request descriptor SG element count (MLIST)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=49adc5d3f8c6bb75e55ebfeab109c5c37dea65e8 ()
CVE: CVE-2016-7421
CVE: CVE-2016-7421
Id:
CVE-2016-7421
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7421
Comment
: The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
834 (Excessive Iteration)
References:
[oss-security] 20160916 CVE Request: Qemu: scsi: pvscsi: infinite loop when processing IO requests (MLIST)
[qemu-devel] 20160915 [PULL 07/17] scsi: pvscsi: limit process IO loop to ring size (MLIST)
[oss-security] 20160916 Re: CVE Request: Qemu: scsi: pvscsi: infinite loop when processing IO requests (MLIST)
92998 (BID)
GLSA-201609-01 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=d251157ac1928191af851d199a9ff255d330bec9 (MISC)
CVE: CVE-2016-7157
CVE: CVE-2016-7157
Id:
CVE-2016-7157
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7157
Comment
: The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSAS_CONFIG_PACK.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References:
[qemu-devel] 20160831 [PATCH 1/2] scsi: mptconfig: fix format string (MLIST)
92775 (BID)
[oss-security] 20160906 CVE Request Qemu: scsi: mptsas: invalid memory access while building configuration pages (MLIST)
[oss-security] 20160906 Re: CVE Request Qemu: scsi: mptsas: invalid memory access while building configuration pages (MLIST)
[qemu-devel] 20160831 [PATCH 2/2] scsi: mptconfig: fix an assert expression (MLIST)
GLSA-201609-01 (GENTOO)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=65a8e1f6413a0f6f79894da710b5d6d43361d27d ()
CVE: CVE-2016-7161
CVE: CVE-2016-7161
Id:
CVE-2016-7161
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7161
Comment
: Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
CVSSv2 Score:
10
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
[qemu-devel] 20160809 [PATCH] hw/net: Fix a heap overflow in xlnx.xps-ethernetlite (MLIST)
93141 (BID)
[oss-security] 20160923 CVE request Qemu: hw: net: Fix a heap overflow in xlnx.xps-ethernetlite (MLIST)
[qemu-devel] 20160809 [PULL 3/3] hw/net: Fix a heap overflow in xlnx.xps-ethernetlite (MLIST)
[oss-security] 20160923 Re: CVE request Qemu: hw: net: Fix a heap overflow in xlnx.xps-ethernetlite (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=a0d1cbdacff5df4ded16b753b38fdd9da6092968 ()
CVE: CVE-2016-7170
CVE: CVE-2016-7170
Id:
CVE-2016-7170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7170
Comment
: The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
129 (Improper Validation of Array Index)
References:
[oss-security] 20160909 CVE Request Qemu: vmware_vga: OOB stack memory access when processing svga command (MLIST)
[qemu-devel] 20160908 [PATCH] vmsvga: correct bitmap and pixmap size checks (MLIST)
[oss-security] 20160909 Re: CVE Request Qemu: vmware_vga: OOB stack memory access when processing svga command (MLIST)
92904 (BID)
openSUSE-SU-2016:3237 (SUSE)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=167d97a3def77ee2dbf6e908b0ecbfe2103977db (MISC)
CVE: CVE-2016-7422
CVE: CVE-2016-7422
Id:
CVE-2016-7422
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7422
Comment
: The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[qemu-devel] 20160915 [PATCH] virtio: add check for descriptor's mapped address (MLIST)
[oss-security] 20160916 CVE request Qemu: virtio: null pointer dereference in virtqueu_map_desc (MLIST)
92996 (BID)
[oss-security] 20160916 Re: CVE request Qemu: virtio: null pointer dereference in virtqueu_map_desc (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201609-01 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=973e7170dddefb491a48df5cba33b2ae151013a0 (MISC)
CVE: CVE-2016-7423
CVE: CVE-2016-7423
Id:
CVE-2016-7423
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7423
Comment
: The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References:
92997 (BID)
[oss-security] 20160916 Re: CVE request Qemu: scsi: mptsas: OOB access when freeing MPTSASRequest object (MLIST)
[qemu-devel] 20160915 [PULL 03/17] scsi: mptsas: use g_new0 to allocate MPTSASRequest object (MLIST)
[oss-security] 20160916 CVE request Qemu: scsi: mptsas: OOB access when freeing MPTSASRequest object (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1376776 (CONFIRM)
GLSA-201611-11 (GENTOO)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=670e56d3ed2918b3861d9216f2c0540d9e9ae0d5 (MISC)
CVE: CVE-2016-7466
CVE: CVE-2016-7466
Id:
CVE-2016-7466
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7466
Comment
: Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[qemu-devel] 20160913 [PATCH v2] usb:xhci:fix memory leak in usb_xhci_exit (MLIST)
93029 (BID)
[oss-security] 20160920 Re: CVE Request Qemu: usb: xhci memory leakage during device unplug (MLIST)
[oss-security] 20160920 CVE Request Qemu: usb: xhci memory leakage during device unplug (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=b53dd4495ced2432a0b652ea895e651d07336f7e (MISC)
CVE: CVE-2016-7908
CVE: CVE-2016-7908
Id:
CVE-2016-7908
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7908
Comment
: The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20161003 CVE request Qemu: net: Infinite loop in mcf_fec_do_tx (MLIST)
[oss-security] 20161003 Re: CVE request Qemu: net: Infinite loop in mcf_fec_do_tx (MLIST)
[qemu-devel] 20160922 [PATCH v2] net: mcf: limit buffer descriptor count (MLIST)
93273 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=070c4b92b8cd5390889716677a0b92444d6e087a (MISC)
CVE: CVE-2016-7909
CVE: CVE-2016-7909
Id:
CVE-2016-7909
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7909
Comment
: The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20161003 Re: CVE Request Qemu: net: pcnet: infinite loop in pcnet_rdra_addr (MLIST)
[qemu-devel] 20160930 [PATCH 1/2] net: pcnet: check rx/tx descriptor ring length (MLIST)
[oss-security] 20161003 CVE Request Qemu: net: pcnet: infinite loop in pcnet_rdra_addr (MLIST)
93275 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-7994
CVE: CVE-2016-7994
Id:
CVE-2016-7994
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7994
Comment
: Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[oss-security] 20161008 Re: CVE request Qemu virtio-gpu: memory leak in virtio_gpu_resource_create_2d (MLIST)
[qemu-devel] 20160919 Re: [PATCH] virtio-gpu: fix memory leak in virtio_gpu_resource_create_2d (MLIST)
93453 (BID)
[oss-security] 20161007 CVE request Qemu virtio-gpu: memory leak in virtio_gpu_resource_create_2d (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
CVE: CVE-2016-7995
CVE: CVE-2016-7995
Id:
CVE-2016-7995
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7995
Comment
: Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
93454 (BID)
[oss-security] 20161008 Re: CVE request Qemu: usb: hcd-ehci: memory leak in ehci_process_itd (MLIST)
[qemu-devel] 20160926 Re: [PATCH] usb: ehci: fix memory leak in ehci_process_itd (MLIST)
[oss-security] 20161007 CVE request Qemu: usb: hcd-ehci: memory leak in ehci_process_itd (MLIST)
openSUSE-SU-2016:3237 (SUSE)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=b16c129daf0fed91febbb88de23dae8271c8898a (MISC)
CVE: CVE-2016-8576
CVE: CVE-2016-8576
Id:
CVE-2016-8576
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8576
Comment
: The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
770 (Allocation of Resources Without Limits or Throttling)
References:
[qemu-devel] 20161007 Re: [PATCH] usb: xHCI: add check to limit command TRB processing (MLIST)
[oss-security] 20161010 Re: CVE request Qemu: usb: xHCI: infinite loop vulnerability in xhci_ring_fetch (MLIST)
93469 (BID)
[oss-security] 20161010 CVE request Qemu: usb: xHCI: infinite loop vulnerability in xhci_ring_fetch (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=05f43d44e4bc26611ce25fd7d726e483f73363ce (MISC)
CVE: CVE-2016-8577
CVE: CVE-2016-8577
Id:
CVE-2016-8577
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8577
Comment
: Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[oss-security] 20161010 CVE request: Qemu: 9pfs: host memory leakage in v9fs_read (MLIST)
93473 (BID)
[oss-security] 20161010 Re: CVE request: Qemu: 9pfs: host memory leakage in v9fs_read (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e95c9a493a5a8d6f969e86c9f19f80ffe6587e19 (MISC)
CVE: CVE-2016-8578
CVE: CVE-2016-8578
Id:
CVE-2016-8578
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8578
Comment
: The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
References:
93474 (BID)
[oss-security] 20161010 CVE request Qemu: 9pfs: potential NULL dereferencein 9pfs routines (MLIST)
[qemu-devel] 20160927 Re: [PATCH] 9pfs: make unmarshal V9fsString more robust (MLIST)
[oss-security] 20161010 Re: CVE request Qemu: 9pfs: potential NULL dereferencein 9pfs routines (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-8668
CVE: CVE-2016-8668
Id:
CVE-2016-8668
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8668
Comment
: The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20161014 CVE request Qemu: net: OOB buffer access in rocker switch emulation (MLIST)
93566 (BID)
[oss-security] 20161015 Re: CVE request Qemu: net: OOB buffer access in rocker switch emulation (MLIST)
[qemu-devel] 20161012 [PATCH] net: rocker: set limit to DMA buffer size (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
CVE: CVE-2016-8909
CVE: CVE-2016-8909
Id:
CVE-2016-8909
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8909
Comment
: The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20161024 CVE request Qemu: audio: intel-hda: infinite loop in processing dma buffer stream (MLIST)
[qemu-devel] 20161020 [PATCH] audio: intel-hda: check stream entry count during transfer (MLIST)
[oss-security] 20161024 Re: CVE request Qemu: audio: intel-hda: infinite loop in processing dma buffer stream (MLIST)
93842 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-8910
CVE: CVE-2016-8910
Id:
CVE-2016-8910
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8910
Comment
: The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[oss-security] 20161024 Re: CVE request Qemu: net: rtl8139: infinite loop while transmit in C+ mode (MLIST)
93844 (BID)
[qemu-devel] 20161024 [PATCH] net: rtl8139: limit processing of ring descript (MLIST)
[oss-security] 20161024 CVE request Qemu: net: rtl8139: infinite loop while transmit in C+ mode (MLIST)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
RHSA-2017:2408 (REDHAT)
RHSA-2017:2392 (REDHAT)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-9101
CVE: CVE-2016-9101
Id:
CVE-2016-9101
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9101
Comment
: Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[oss-security] 20161030 Re: CVE request Qemu: net: eepro100 memory leakage at device unplug (MLIST)
[qemu-devel] 20161013 [PATCH] eepro100: Fix memory leak and simplify code for VMStateDescription (MLIST)
[oss-security] 20161028 CVE request Qemu: net: eepro100 memory leakage at device unplug (MLIST)
93957 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201701-49 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-9102
CVE: CVE-2016-9102
Id:
CVE-2016-9102
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9102
Comment
: Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[oss-security] 20161028 CVE request Qemu: 9pfs: memory leakage when creating extended attribute (MLIST)
[qemu-devel] 20161010 Re: [PATCH] 9pfs: fix memory leak in v9fs_xattrcreate (MLIST)
[oss-security] 20161030 Re: CVE request Qemu: 9pfs: memory leakage when creating extended attribute (MLIST)
93962 (BID)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=ff55e94d23ae94c8628b0115320157c763eb3e06 (MISC)
CVE: CVE-2016-9104
CVE: CVE-2016-9104
Id:
CVE-2016-9104
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9104
Comment
: Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20161030 Re: CVE request Qemu: 9pfs: integer overflow leading to OOB access (MLIST)
[qemu-devel] 20161013 Re: [PATCH v3 3/3] 9pfs: fix integer overflow issue in xattr read/write (MLIST)
[oss-security] 20161028 CVE request Qemu: 9pfs: integer overflow leading to OOB access (MLIST)
93956 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
CVE: CVE-2016-9105
CVE: CVE-2016-9105
Id:
CVE-2016-9105
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9105
Comment
: Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[qemu-devel] 20161012 Re: [PATCH] 9pfs: fix memory leak in v9fs_link (MLIST)
[oss-security] 20161028 CVE request Qemu: memory leakage in v9fs_link (MLIST)
[oss-security] 20161030 Re: CVE request Qemu: memory leakage in v9fs_link (MLIST)
93965 (BID)
openSUSE-SU-2016:3237 (SUSE)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=4c1586787ff43c9acd18a56c12d720e3e6be9f7c (MISC)
CVE: CVE-2016-9103
CVE: CVE-2016-9103
Id:
CVE-2016-9103
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9103
Comment
: The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20161028 CVE request Qemu: 9pfs: information leakage via xattribute (MLIST)
[oss-security] 20161030 Re: CVE request Qemu: 9pfs: information leakage via xattribute (MLIST)
[qemu-devel] 20161010 Re: [PATCH 1/2] 9pfs: fix information leak in xattr read (MLIST)
93955 (BID)
GLSA-201611-11 (GENTOO)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=eb687602853b4ae656e9236ee4222609f3a6887d (MISC)
CVE: CVE-2016-9106
CVE: CVE-2016-9106
Id:
CVE-2016-9106
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9106
Comment
: Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[oss-security] 20161028 CVE request Qemu: 9pfs: memory leakage in v9fs_write (MLIST)
[oss-security] 20161030 Re: CVE request Qemu: 9pfs: memory leakage in v9fs_write (MLIST)
[qemu-devel] 20161012 Re: [PATCH v2] 9pfs: fix memory leak in v9fs_write (MLIST)
93964 (BID)
openSUSE-SU-2016:3237 (SUSE)
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update (MLIST)
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fdfcc9aeea1492f4b819a24c94dfb678145b1bf9 (MISC)
Content available only for registered users!
ovaldb@altx-soft.com