CVE-2016-1568
published 2016-04-12CVE-2016-1568: Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance…
PriorityP339high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.53%
41.8th percentile
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.5+dfsg-2 (bookworm) | qemu 1:2.5+dfsg-2 (bookworm) |
| qemu | qemu | <= 2.5.1.1 | — |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.22 | 2.0.0+dfsg-2ubuntu1.22 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-02-03·CVSS 6.0
CVE-2015-7549 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-7549)
Lian Yihan discovered that QEMU incorrectly handled the VNC server. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2015-8504)
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on th
Red Hat
Qemu: ide: ahci use-after-free vulnerability in aio port commands
vendor_redhat·2016-01-08·CVSS 8.8
CVE-2016-1568 [HIGH] CWE-416 Qemu: ide: ahci use-after-free vulnerability in aio port commands
Qemu: ide: ahci use-after-free vulnerability in aio port commands
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
A use-after-free flaw was found in the way QEMU's IDE AHCI emulator processed certain AHCI Native Command Queuing (NCQ) AIO commands. A privileged guest user could use this flaw to crash the QEMU process instance or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
Statement: The vector of exploit requires to enable TIOCSTI with sysctl, because it
is by default disabled since RHEL9 and on. Then, the user would have to
be in roo
Debian
CVE-2016-1568: qemu - Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI ...
vendor_debian·2016·CVSS 8.8
CVE-2016-1568 [HIGH] CVE-2016-1568: qemu - Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI ...
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-2)
bullseye: resolved (fixed in 1:2.5+dfsg-2)
forky: resolved (fixed in 1:2.5+dfsg-2)
sid: resolved (fixed in 1:2.5+dfsg-2)
trixie: resolved (fixed in 1:2.5+dfsg-2)
GHSA
GHSA-gx29-hhc2-825w: Use-after-free vulnerability in hw/ide/ahci
ghsa_unreviewed·2022-05-13
CVE-2016-1568 [HIGH] CWE-416 GHSA-gx29-hhc2-825w: Use-after-free vulnerability in hw/ide/ahci
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
OSV
CVE-2016-1568: Use-after-free vulnerability in hw/ide/ahci
osv·2016-04-12·CVSS 8.8
CVE-2016-1568 [HIGH] CVE-2016-1568: Use-after-free vulnerability in hw/ide/ahci
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-02-03·CVSS 6.0
CVE-2015-7549 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-7549)
Lian Yihan discovered that QEMU incorrectly handled the VNC server. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2015-8504)
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Qinghao Tang discovered th
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1568 qemu: Use-after-free vulnerability in ahci [fedora-all]
bugzilla·2016-01-08·CVSS 8.8
CVE-2016-1568 [HIGH] CVE-2016-1568 qemu: Use-after-free vulnerability in ahci [fedora-all]
CVE-2016-1568 qemu: Use-after-free vulnerability in ahci [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2016-1568 xen: qemu: Use-after-free vulnerability in ahci [fedora-all]
bugzilla·2016-01-08·CVSS 8.8
CVE-2016-1568 [HIGH] CVE-2016-1568 xen: qemu: Use-after-free vulnerability in ahci [fedora-all]
CVE-2016-1568 xen: qemu: Use-after-free vulnerability in ahci [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-1568 Qemu: ide: ahci use-after-free vulnerability in aio port commands
bugzilla·2015-12-04·CVSS 8.8
CVE-2016-1568 [HIGH] CVE-2016-1568 Qemu: ide: ahci use-after-free vulnerability in aio port commands
CVE-2016-1568 Qemu: ide: ahci use-after-free vulnerability in aio port commands
Qemu emulator built with the IDE AHCI Emulation support is vulnerable to
a use after free issue. It could occur after processing AHCI Native
Command Queuing(NCQ) AIO commands.
A privileged user inside guest could use this flaw to crash the Qemu process
instance or potentially execute arbitrary code with privileges of the Qemu
process on the host.
Upstream fix:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg01184.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/01/09/2
Discussion:
Statement:
(none)
---
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1297024]
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1297023]
---
qemu-2
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=4ab0359a8ae182a7ac5c99609667273167703fabhttp://rhn.redhat.com/errata/RHSA-2016-0084.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0087.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0088.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2016/01/09/1http://www.openwall.com/lists/oss-security/2016/01/09/2http://www.securityfocus.com/bid/80191http://www.securitytracker.com/id/1034859https://security.gentoo.org/glsa/201602-01http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=4ab0359a8ae182a7ac5c99609667273167703fabhttp://rhn.redhat.com/errata/RHSA-2016-0084.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0087.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0088.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2016/01/09/1http://www.openwall.com/lists/oss-security/2016/01/09/2http://www.securityfocus.com/bid/80191http://www.securitytracker.com/id/1034859https://security.gentoo.org/glsa/201602-01
2016-04-12
Published