The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Oct 5, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Oct 5, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 21, 2016 |
| Suse | — | Upgrade qemu-microvmUpgrade qemu-chardev-spiceUpgrade qemu-audio-spiceUpgrade qemu-s390xUpgrade qemu-block-rbdUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ksmUpgrade qemu-s390Upgrade qemu-guest-agentUpgrade qemu-block-curlUpgrade qemu-audio-alsaUpgrade qemu-langUpgrade qemu-sgabiosUpgrade qemu-kvmUpgrade qemu-ipxeUpgrade qemu-ui-gtkUpgrade qemu-chardev-baumUpgrade qemu-ui-spice-coreUpgrade qemu-block-sshUpgrade qemu-vgabiosUpgrade qemu-ppcUpgrade qemu-ui-openglUpgrade qemu-seabiosUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-usb-redirectUpgrade qemuUpgrade qemu-toolsUpgrade qemu-ui-spice-appUpgrade qemu-block-iscsiUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-skibootUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-ui-cursesUpgrade qemu-audio-ossUpgrade qemu-armUpgrade qemu-audio-paUpgrade qemu-hw-display-qxlUpgrade qemu-x86 | Nov 23, 2016 | Oct 5, 2016 |
| Ubuntu | — | Upgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-miscUpgrade qemu-system-aarch64Upgrade qemu-system-ppcUpgrade qemu-system-sparc | Apr 21, 2017 | Oct 5, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub