CVE-2016-2391
published 2016-06-16CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service…
PriorityP414medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.40%
32.3th percentile
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.6+dfsg-1 (bookworm) | qemu 1:2.6+dfsg-1 (bookworm) |
| qemu | qemu | <= 2.5.1.1 | — |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.24 | 2.0.0+dfsg-2ubuntu1.24 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.1 | 1:2.5+dfsg-5ubuntu10.1 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU i
Red Hat
Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
vendor_redhat·2016-02-16·CVSS 5.0
CVE-2016-2391 [MEDIUM] CWE-476 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
A NULL pointer dereference flaw was found in the QEMU emulator built with USB OHCI emulation support. The flaw could occur when OHCI transitions to the OHCI_USB_OPERATIONAL state, leading to the creation of multiple EOF timers. A privileged user inside a guest could exploit this flaw to crash the QEMU process on the host (denial of service).
Statement: This has been rated as having Low security impact and is not currently
planned to be addressed in future updates
Debian
CVE-2016-2391: qemu - The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c...
vendor_debian·2016·CVSS 5.0
CVE-2016-2391 [MEDIUM] CVE-2016-2391: qemu - The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c...
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolved (fixed in 1:2.6+dfsg-1)
sid: resolved (fixed in 1:2.6+dfsg-1)
trixie: resolved (fixed in 1:2.6+dfsg-1)
GHSA
GHSA-g442-4wgf-h9jr: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci
ghsa_unreviewed·2022-05-13
CVE-2016-2391 [MEDIUM] CWE-476 GHSA-g442-4wgf-h9jr: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
OSV
CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci
osv·2016-06-16·CVSS 5.0
CVE-2016-2391 [MEDIUM] CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU incorrectly handled NE2000 emulation
support. A priv
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2391 qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
bugzilla·2016-02-16·CVSS 5.0
CVE-2016-2391 [MEDIUM] CVE-2016-2391 qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
CVE-2016-2391 qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-2391 xen: qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
bugzilla·2016-02-16·CVSS 5.0
CVE-2016-2391 [MEDIUM] CVE-2016-2391 xen: qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
CVE-2016-2391 xen: qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-2391 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
bugzilla·2016-02-04·CVSS 5.0
CVE-2016-2391 [MEDIUM] CVE-2016-2391 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
CVE-2016-2391 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
Qemu emulator built with the USB OHCI emulation support is vulnerable to a null pointer dereference issue. It could occur when OHCI transitions to a OHCI_USB_OPERATIONAL state, leading to creation of multiple eof timers.
A privileged user inside guest could use this flaw to crash the Qemu process on the host, resulting in DoS.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-02/msg03471.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/02/16/2
Discussion:
Statement:
This has been rated as having Low security impact and is not currently
planned to be addressed in future updates. For additional information, refer
to the Red Hat Enterprise Linux Life Cycle
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa1298c2d623522eda7b4f1f721fcb935abb7360http://www.openwall.com/lists/oss-security/2016/02/16/2http://www.securityfocus.com/bid/83263http://www.ubuntu.com/usn/USN-2974-1https://bugzilla.redhat.com/show_bug.cgi?id=1304794https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-02/msg03374.htmlhttp://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa1298c2d623522eda7b4f1f721fcb935abb7360http://www.openwall.com/lists/oss-security/2016/02/16/2http://www.securityfocus.com/bid/83263http://www.ubuntu.com/usn/USN-2974-1https://bugzilla.redhat.com/show_bug.cgi?id=1304794https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-02/msg03374.html
2016-06-16
Published