PT-2016-4900 · Qemu+5 · Qemu+5

Donghai Zdh

·

Published

2015-10-12

·

Updated

2024-06-15

·

CVE-2016-1714

CVSS v3.1

8.1

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.4
Description The issue concerns the fw cfg write and fw cfg read functions in QEMU, which can be exploited by guest OS users with the CAP SYS RAWIO privilege to cause a denial of service, including out-of-bounds read or write access and process crash, or possibly execute arbitrary code. This is achieved by providing an invalid current entry value in a firmware configuration.
Recommendations For QEMU versions prior to 2.4, update to version 2.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Firmware Configuration device emulation support to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1865
CESA-2016_0082
CESA-2016_0083
CVE-2016-1714
DSA-3469-1
DSA-3470-1
DSA-3471-1
MGASA-2016-0023
OPENSUSE-SU-2016_0914-1
OPENSUSE-SU-2016_0995-1
OPENSUSE-SU-2016_1750-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2024:10196-1
OPENSUSE-SU-2024:11287-1
RHSA-2016:0081
RHSA-2016:0082
RHSA-2016:0083
RHSA-2016:0084
RHSA-2016:0085
RHSA-2016:0086
RHSA-2016:0087
RHSA-2016:0088
RHSA-2016_0082
RHSA-2016_0083
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1154-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1703-1
SUSE-SU-2016:1745-1
SUSE-SU-2016:1785-1
USN-2891-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu