Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2857

Опубликовано: 17 фев. 2016
Источник: redhat
CVSS3: 4.7
CVSS2: 4.3
EPSS Низкий

Описание

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.

An out-of-bounds read-access flaw was found in the QEMU emulator built with IP checksum routines. The flaw could occur when computing a TCP/UDP packet's checksum, because a QEMU function used the packet's payload length without checking against the data buffer's size. A user inside a guest could use this flaw to crash the QEMU process (denial of service).

Отчет

This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 6qemu-kvm-rhevAffected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevNot affected
Red Hat OpenStack Platform 11 (Ocata)qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2017:030923.02.2017
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2017:008317.01.2017
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6qemu-kvm-rhevFixedRHSA-2017:033427.02.2017
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qemu-kvm-rhevFixedRHSA-2016:270614.11.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7qemu-kvm-rhevFixedRHSA-2016:270514.11.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7qemu-kvm-rhevFixedRHSA-2016:270414.11.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1296567Qemu: net: out of bounds read in net_checksum_calculate()

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.4
ubuntu
больше 9 лет назад

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.

CVSS3: 8.4
nvd
больше 9 лет назад

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.

CVSS3: 8.4
debian
больше 9 лет назад

The net_checksum_calculate function in net/checksum.c in QEMU allows l ...

CVSS3: 8.4
github
больше 3 лет назад

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.

oracle-oval
почти 9 лет назад

ELSA-2017-0083: qemu-kvm security and bug fix update (LOW)

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3

4.3 Medium

CVSS2