Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7995

Опубликовано: 10 дек. 2016
Источник: debian

Описание

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.8+dfsg-1package
qemunot-affectedjessiepackage
qemunot-affectedwheezypackage
qemu-kvmnot-affectedpackage

Примечания

  • https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg06609.html

  • https://bugzilla.redhat.com/show_bug.cgi?id=1382668

  • Vulnerable code introduced in 49d925ce50383a286278143c05511d30ec41a36e

  • Though this commit fixed an OOB read access issue which might need

  • potentially a new separate CVE id if it does not have one yet.

Связанные уязвимости

CVSS3: 6
ubuntu
около 9 лет назад

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

CVSS3: 3
redhat
больше 9 лет назад

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

CVSS3: 6
nvd
около 9 лет назад

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

CVSS3: 6
github
больше 3 лет назад

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

suse-cvrf
около 9 лет назад

Security update for xen