QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 29, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2016 |
| Suse | — | Upgrade qemu-block-rbdUpgrade xen-kmp-paeUpgrade qemu-ipxeUpgrade xen-toolsUpgrade qemu-seabiosUpgrade qemu-guest-agentUpgrade xen-develUpgrade qemu-block-curlUpgrade qemu-toolsUpgrade qemu-langUpgrade qemu-ppcUpgrade qemu-vgabiosUpgrade xen-tools-domUUpgrade xenUpgrade qemu-s390Upgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade qemu-kvmUpgrade xen-libsUpgrade qemu-x86Upgrade qemu-sgabiosUpgrade xen-doc-htmlUpgrade qemu | Mar 28, 2016 | Mar 24, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub