PT-2016-3004 · Qemu+3 · Qemu+3

Publicado

2016-12-23

·

Atualizado

2023-02-13

·

CVE-2016-9911

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to an uncontrolled resource consumption in the Virtio GPU emulator hardware of QEMU. It may allow a local attacker to compromise the confidentiality, integrity, and availability of data. Additionally, there is a memory leakage issue in QEMU when built with USB EHCI Emulation support, which could occur while processing packet data in ehci init transfer(). This could be used by a guest user or process to leak host memory, resulting in a denial of service for the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1043
BDU:2017-00073
CVE-2016-9911
DLA-1497-1
DLA-764-1
DLA-765-1
OPENSUSE-SU-2017_0194-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:0127-1
SUSE-SU-2017:0570-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0661-1
SUSE-SU-2017:0718-1
SUSE-SU-2017:1135-1
SUSE-SU-2017:1241-1
SUSE-SU-2017:3084-1
USN-3261-1

Produtos afetados

Alt Linux
Qemu
Suse
Ubuntu