Back to search
CVE-2016-7908
Published: Oct 5, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20161003 CVE request Qemu: net: Infinite loop in mcf_fec_do_tx
mailing-list
x_refsource_MLIST
[qemu-devel] 20160922 [PATCH v2] net: mcf: limit buffer descriptor count
mailing-list
x_refsource_MLIST
GLSA-201611-11
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2016:3237
vendor-advisory
x_refsource_SUSE
93273
vdb-entry
x_refsource_BID
[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update
mailing-list
x_refsource_MLIST
[oss-security] 20161003 Re: CVE request Qemu: net: Infinite loop in mcf_fec_do_tx
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now