Back to search
CVE-2016-7422
Published: Dec 10, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[qemu-devel] 20160915 [PATCH] virtio: add check for descriptor's mapped address
mailing-list
x_refsource_MLIST
RHSA-2017:2392
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2016:3237
vendor-advisory
x_refsource_SUSE
GLSA-201609-01
vendor-advisory
x_refsource_GENTOO
92996
vdb-entry
x_refsource_BID
[oss-security] 20160916 Re: CVE request Qemu: virtio: null pointer dereference in virtqueu_map_desc
mailing-list
x_refsource_MLIST
[oss-security] 20160916 CVE request Qemu: virtio: null pointer dereference in virtqueu_map_desc
mailing-list
x_refsource_MLIST
RHSA-2017:2408
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now