QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 29, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Dec 29, 2016 |
| Suse | — | Upgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-s390xUpgrade qemu-toolsUpgrade qemu-langUpgrade qemu-armUpgrade qemu-sgabiosUpgrade qemu-x86Upgrade qemu-chardev-spiceUpgrade qemu-ppcUpgrade qemu-audio-ossUpgrade qemu-guest-agentUpgrade qemu-ui-openglUpgrade qemu-audio-paUpgrade qemu-hw-display-qxlUpgrade qemu-vgabiosUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-block-sshUpgrade qemuUpgrade qemu-audio-alsaUpgrade qemu-seabiosUpgrade qemu-block-curlUpgrade qemu-ui-cursesUpgrade qemu-chardev-baumUpgrade qemu-microvmUpgrade qemu-skibootUpgrade qemu-ipxeUpgrade qemu-ui-spice-coreUpgrade qemu-audio-spiceUpgrade qemu-block-iscsiUpgrade qemu-s390Upgrade qemu-ui-gtkUpgrade qemu-hw-usb-redirectUpgrade qemu-kvmUpgrade qemu-ksmUpgrade qemu-ui-spice-app | Jan 14, 2017 | Dec 29, 2016 |
| Ubuntu | — | Upgrade qemu-system-sparcUpgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-x86Upgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-armUpgrade qemu-system-aarch64Upgrade qemu-system-s390x | Apr 21, 2017 | Dec 29, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub