QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could use this flaw to crash the QEMU process instance resulting in DoS.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-qemu | Jul 30, 2024 | Dec 29, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-app-emulation-qemu | Oct 30, 2017 | Dec 29, 2016 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jan 28, 2016 |
| Suse | — | suse-upgrade-qemususe-upgrade-qemu-block-curlsuse-upgrade-qemu-block-rbdsuse-upgrade-qemu-guest-agentsuse-upgrade-qemu-ipxesuse-upgrade-qemu-kvmsuse-upgrade-qemu-langsuse-upgrade-qemu-ppcsuse-upgrade-qemu-s390suse-upgrade-qemu-seabiossuse-upgrade-qemu-sgabiossuse-upgrade-qemu-toolssuse-upgrade-qemu-vgabiossuse-upgrade-qemu-x86 | Jul 26, 2016 | Jun 29, 2016 |
| Ubuntu | ubuntu-upgrade-qemu-kvmubuntu-upgrade-qemu-systemubuntu-upgrade-qemu-system-aarch64ubuntu-upgrade-qemu-system-armubuntu-upgrade-qemu-system-mipsubuntu-upgrade-qemu-system-miscubuntu-upgrade-qemu-system-ppcubuntu-upgrade-qemu-system-sparcubuntu-upgrade-qemu-system-x86 | Feb 3, 2016 | Feb 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub