PT-2016-7791 · Qemu+5 · Qemu+5

Prasad Pandit

·

Published

2016-12-31

·

Updated

2021-08-04

·

CVE-2016-9603

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.9
Description A heap buffer overflow issue was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support. The issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. This could allow a privileged user/process inside a guest to crash the QEMU process or potentially execute arbitrary code on the host with privileges of the QEMU process.
Recommendations For QEMU versions prior to 2.9, update to version 2.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the VNC display driver support until a patch is available. Avoid using the VNC client to update its display after a VGA operation is performed by a guest until the issue is resolved.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1521
CESA-2017_0987
CESA-2017_1206
CVE-2016-9603
DLA-1035-1
DLA-1270-1
DLA-1497-1
DLA-939-1
OPENSUSE-SU-2017_1221-1
OPENSUSE-SU-2017_1872-1
OPENSUSE-SU-2017_2398-1
RHSA-2017:0980
RHSA-2017:0981
RHSA-2017:0982
RHSA-2017:0983
RHSA-2017:0984
RHSA-2017:0985
RHSA-2017:0987
RHSA-2017:0988
RHSA-2017:1205
RHSA-2017:1206
RHSA-2017:1441
RHSA-2017_0987
RHSA-2017_1206
SUSE-SU-2017:1080-1
SUSE-SU-2017:1081-1
SUSE-SU-2017:1143-1
SUSE-SU-2017:1145-1
SUSE-SU-2017:1146-1
SUSE-SU-2017:1147-1
SUSE-SU-2017:1774-1
SUSE-SU-2017:2326-1
SUSE-SU-2017:2946-1
SUSE-SU-2017:2963-1
SUSE-SU-2017:2969-1
SUSE-SU-2017:3084-1
SUSE-SU-2017_1080-1
SUSE-SU-2017_1081-1
SUSE-SU-2017_1143-1
SUSE-SU-2017_1145-1
SUSE-SU-2017_1146-1
SUSE-SU-2017_1147-1
SUSE-SU-2017_2326-1
USN-3261-1
USN-3268-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu