PT-2016-2680 · Qemu+3 · Qemu+3

Li Qiang

·

Published

2016-05-30

·

Updated

2024-06-15

·

CVE-2016-4952

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to QEMU's VMWARE PVSCSI paravirtual SCSI bus emulation support. It allows local guest OS administrators to cause a denial of service via vectors related to the PVSCSI CMD SETUP RINGS or PVSCSI CMD SETUP MSG RING SCSI commands. This can lead to an out-of-bounds array access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1937
ALT-PU-2017-1043
BDU:2016-02072
CVE-2016-4952
DLA-1599-1
OPENSUSE-SU-2016_1750-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2016_2497-1
OPENSUSE-SU-2024:10233-1
OPENSUSE-SU-2024:10285-1
SUSE-SU-2016:1560-1
SUSE-SU-2016:1703-1
SUSE-SU-2016:2093-1
SUSE-SU-2016:2100-1
SUSE-SU-2016:2533-1
USN-3047-1
USN-3047-2

Affected Products

Alt Linux
Qemu
Suse
Ubuntu