Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kvmUpgrade kvm-toolsUpgrade kmod-kvmUpgrade kvm-qemu-img | Dec 1, 2016 | Feb 12, 2010 |
| Oracle_linux | — | Upgrade kvmUpgrade kvm-toolsUpgrade kmod-kvmUpgrade kvm-qemu-img | Oct 16, 2024 | Feb 12, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub