The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Oct 10, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Oct 10, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2016 |
| Suse | — | Upgrade qemu-armUpgrade qemu-chardev-spiceUpgrade qemu-audio-spiceUpgrade qemu-block-sshUpgrade qemu-ui-spice-appUpgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-display-virtio-vgaUpgrade qemuUpgrade qemu-s390xUpgrade qemu-hw-display-qxlUpgrade qemu-langUpgrade qemu-seabiosUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-guest-agentUpgrade qemu-ipxeUpgrade qemu-skibootUpgrade qemu-block-iscsiUpgrade qemu-audio-ossUpgrade qemu-ui-openglUpgrade qemu-toolsUpgrade qemu-ui-gtkUpgrade qemu-audio-alsaUpgrade qemu-ui-cursesUpgrade qemu-ppcUpgrade qemu-ksmUpgrade qemu-x86Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-s390Upgrade qemu-audio-paUpgrade qemu-microvmUpgrade qemu-kvmUpgrade qemu-block-curlUpgrade qemu-ui-spice-coreUpgrade qemu-vgabiosUpgrade qemu-hw-usb-redirectUpgrade qemu-chardev-baumUpgrade qemu-sgabios | Jul 21, 2017 | Oct 10, 2016 |
| Ubuntu | — | Upgrade qemu-system-aarch64Upgrade qemu-system-mipsUpgrade qemu-system-x86Upgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-kvmUpgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-system-sparc | Nov 9, 2016 | Oct 10, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub