vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 30, 2017 | Aug 26, 2014 |
| Debian | — | Upgrade qemu | Jul 30, 2024 | Aug 26, 2014 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Aug 26, 2014 |
| Ubuntu | — | Upgrade qemu-system-sparcUpgrade qemu-kvmUpgrade qemu-system-armUpgrade qemu-system-aarch64Upgrade qemu-system-miscUpgrade qemu-system-mipsUpgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-system-x86 | Nov 8, 2024 | Aug 26, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub