cbcvebase.
CVE-2016-1981
published 2016-12-29

CVE-2016-1981: QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.44%
36.3th percentile
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instance resulting in DoS.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.5+dfsg-5 (bookworm)qemu 1:2.5+dfsg-5 (bookworm)
qemuqemu<= 2.5.1.1
qemuqemu>= 0 < 1:2.5+dfsg-51:2.5+dfsg-5
qemuqemu>= 0 < 1:2.5+dfsg-51:2.5+dfsg-5
qemuqemu>= 0 < 1:2.5+dfsg-51:2.5+dfsg-5
qemuqemu>= 0 < 1:2.5+dfsg-51:2.5+dfsg-5
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.222.0.0+dfsg-2ubuntu1.22

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.