PT-2017-10387 · Qemu Team+3 · Qemu+3

Jiangxin

+2

·

Published

2017-01-13

·

Updated

2023-02-13

·

CVE-2016-9922

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (aka Quick Emulator) versions (affected versions not specified)
Description The issue allows local guest OS privileged users to cause a denial of service, resulting in a divide-by-zero error and QEMU process crash. This is achieved through vectors involving blit pitch values when cirrus graphics mode is set to VGA.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1043
CVE-2016-9922
DLA-1497-1
DLA-764-1
DLA-765-1
OPENSUSE-SU-2017_0194-1
OPENSUSE-SU-2017_0665-1
OPENSUSE-SU-2017_0707-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:0127-1
SUSE-SU-2017:0570-1
SUSE-SU-2017:0571-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0625-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0661-1
SUSE-SU-2017:0718-1
SUSE-SU-2017:1135-1
SUSE-SU-2017:1241-1
SUSE-SU-2017:3084-1
USN-3261-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu