Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
CVSS Details
- CVSS 3.1 Base Score: 7.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Feb 20, 2019 | Apr 11, 2017 |
| Freebsd | — | Upgrade qemu-user-staticUpgrade qemu-sbrunoUpgrade qemu-develUpgrade qemu | Dec 10, 2025 | Jan 3, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Apr 11, 2017 |
| Ubuntu | — | Upgrade qemu-system-armUpgrade qemu-system-ppcUpgrade qemu-kvmUpgrade qemu-system-miscUpgrade qemu-system-mipsUpgrade qemu-system-aarch64Upgrade qemu-systemUpgrade qemu-system-x86Upgrade qemu-system-sparc | Feb 3, 2016 | Feb 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub