PT-2016-3004 · Qemu+3 · Qemu+3

Published

2016-12-23

·

Updated

2023-02-13

·

CVE-2016-9911

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to an uncontrolled resource consumption in the Virtio GPU emulator hardware of QEMU. It may allow a local attacker to compromise the confidentiality, integrity, and availability of data. Additionally, there is a memory leakage issue in QEMU when built with USB EHCI Emulation support, which could occur while processing packet data in ehci init transfer(). This could be used by a guest user or process to leak host memory, resulting in a denial of service for the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1043
BDU:2017-00073
CVE-2016-9911
DLA-1497-1
DLA-764-1
DLA-765-1
OPENSUSE-SU-2017_0194-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:0127-1
SUSE-SU-2017:0570-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0661-1
SUSE-SU-2017:0718-1
SUSE-SU-2017:1135-1
SUSE-SU-2017:1241-1
SUSE-SU-2017:3084-1
USN-3261-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu