PT-2016-3006 · Qemu+3 · Qemu+3

Published

2016-12-23

·

Updated

2024-06-15

·

CVE-2016-9907

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Qemu (affected versions not specified)
Description The issue is related to a memory leakage flaw in Qemu's USB redirector, specifically when destroying the USB redirector in usbredir handle destroy. This could allow a guest user or process to leak host memory, potentially resulting in a denial of service (DoS) for the host. The flaw may also lead to unauthorized access, integrity, and availability issues due to uncontrolled resource consumption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1043
BDU:2017-00075
CVE-2016-9907
DLA-1497-1
OPENSUSE-SU-2017_0194-1
OPENSUSE-SU-2024:11287-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:0127-1
SUSE-SU-2017:0570-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0661-1
SUSE-SU-2017:1135-1
SUSE-SU-2017:1241-1
SUSE-SU-2017:3084-1
USN-3261-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu