Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 23, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Dec 23, 2016 |
| Suse | — | Upgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-block-rbdUpgrade qemu-armUpgrade qemu-langUpgrade qemu-s390xUpgrade qemu-ppcUpgrade qemuUpgrade qemu-block-sshUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-hw-usb-redirectUpgrade qemu-guest-agentUpgrade qemu-audio-ossUpgrade qemu-toolsUpgrade qemu-audio-paUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-chardev-spiceUpgrade qemu-x86Upgrade qemu-hw-display-qxlUpgrade qemu-ui-openglUpgrade qemu-vgabiosUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-sgabiosUpgrade qemu-microvmUpgrade qemu-ui-gtkUpgrade qemu-block-iscsiUpgrade qemu-chardev-baumUpgrade qemu-ui-cursesUpgrade qemu-kvmUpgrade qemu-seabiosUpgrade qemu-skibootUpgrade qemu-audio-alsaUpgrade qemu-ui-spice-appUpgrade qemu-audio-spiceUpgrade qemu-s390Upgrade qemu-block-curlUpgrade qemu-ui-spice-coreUpgrade qemu-ksmUpgrade qemu-ipxe | Jan 14, 2017 | Dec 23, 2016 |
| Ubuntu | — | Upgrade qemu-system-miscUpgrade qemu-system-s390xUpgrade qemu-system-x86Upgrade qemu-system-armUpgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-sparcUpgrade qemu-system-aarch64 | Apr 21, 2017 | Dec 23, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub