PT-2016-4940 · Qemu+5 · Qemu+5

Laszlo Ersek

·

Published

2016-01-22

·

Updated

2024-06-15

·

CVE-2016-1981

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to an infinite loop that could occur while processing data via transmit or receive descriptors in QEMU, specifically when the initial receive/transmit descriptor head is set outside the allocated descriptor buffer. A privileged user inside a guest could exploit this to crash the QEMU instance, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1565
CESA-2016_2585
CVE-2016-1981
DSA-3469-1
DSA-3470-1
DSA-3471-1
MGASA-2016-0176
OPENSUSE-SU-2016_0914-1
OPENSUSE-SU-2016_0995-1
OPENSUSE-SU-2016_1750-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2024:10196-1
RHSA-2016:2585
RHSA-2016_2585
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1154-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1703-1
SUSE-SU-2016:1745-1
SUSE-SU-2016:1785-1
USN-2891-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu