PT-2017-7714 · Qemu+3 · Qemu+3

Zhenhao Hong

·

Published

2017-01-17

·

Updated

2023-02-13

·

CVE-2016-10029

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue allows local guest OS users to cause a denial of service, resulting in an out-of-bounds read and process crash. This is achieved via a scanout id in a VIRTIO GPU CMD SET SCANOUT command that is larger than num scanouts. The virtio gpu set scanout function in QEMU, built with Virtio GPU Device emulator support, is the affected component.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1043
CVE-2016-10029
OPENSUSE-SU-2017_0707-1
OPENSUSE-SU-2017_1872-1
SUSE-SU-2017:0625-1
SUSE-SU-2017:1774-1
USN-3261-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu