PT-2016-5234 · Qemu+3 · Qemu+3
Yang Hongke
·
Published
2016-03-04
·
Updated
2024-06-15
·
CVE-2016-2841
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 2.5.1
Description
The issue allows local guest OS administrators to cause a denial of service, resulting in an infinite loop and QEMU process crash. This is achieved by providing crafted values for the
PSTART and PSTOP registers, which are involved in ring buffer control.Recommendations
For versions prior to 2.5.1, update to version 2.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NE2000 NIC emulation support to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Qemu
Suse
Ubuntu