Back to search
CVE-2016-6490
Published: Dec 10, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20160728 CVE Request Qemu: virtio: infinite loop in virtqueue_pop
mailing-list
x_refsource_MLIST
[oss-security] 20160728 Re: CVE Request Qemu: virtio: infinite loop in virtqueue_pop
mailing-list
x_refsource_MLIST
GLSA-201609-01
vendor-advisory
x_refsource_GENTOO
[qemu-devel] 20160726 [PATCH] virtio: check vring descriptor buffer length
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now