Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9914

Опубликовано: 29 дек. 2016
Источник: debian
EPSS Низкий

Описание

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.8+dfsg-1package
qemuno-dsawheezypackage
qemu-kvmremovedpackage
qemu-kvmno-dsawheezypackage

Примечания

  • https://lists.gnu.org/archive/html/qemu-devel/2016-11/msg03278.html

  • Fixed by: http://git.qemu.org/?p=qemu.git;a=commit;h=702dbcc274e2ca43be20ba64c758c0ca57dab91d (v2.8.0-rc2)

  • https://www.openwall.com/lists/oss-security/2016/12/06/11

  • proxy and handle drivers not included during compilation in wheezy, so the cleanup function is never implemented:

  • see debian-lts ML: https://lists.debian.org/debian-lts/2016/12/msg00136.html

EPSS

Процентиль: 22%
0.00071
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

CVSS3: 3
redhat
около 9 лет назад

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

CVSS3: 6.5
nvd
около 9 лет назад

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

CVSS3: 6.5
github
больше 3 лет назад

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

fstec
около 9 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00071
Низкий