Description
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_dataout function.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: High
Affected Packages4 packages
🔴Vulnerability Details
3GHSAGHSA-fqw6-89c5-2q6q: Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network↗2022-05-14 ▶ OSVCVE-2016-2538: Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network↗2016-06-16 ▶ OSVqemu, qemu-kvm vulnerabilities↗2016-05-12 ▶ 📋Vendor Advisories
3UbuntuQEMU vulnerabilities↗2016-05-12 ▶ Red HatQemu: usb: integer overflow in remote NDIS control message handling↗2016-02-05 ▶ DebianCVE-2016-2538: qemu - Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c)...↗2016 ▶ 💬Community
3BugzillaCVE-2016-2538 xen: qemu: Integer overflow in usb module causing memory leak and DoS [fedora-all]↗2016-02-09 ▶ BugzillaCVE-2016-2538 qemu: Integer overflow in usb module causing memory leak and DoS [fedora-all]↗2016-02-09 ▶ BugzillaCVE-2016-2538 Qemu: usb: integer overflow in remote NDIS control message handling↗2016-01-29 ▶