cbcvebase.
CVE-2016-2858
published 2016-04-07

CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via…

PriorityP426medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.39%
32.0th percentile
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianqemu< qemu 1:2.6+dfsg-1 (bookworm)qemu 1:2.6+dfsg-1 (bookworm)
qemuqemu<= 2.5.1.1
qemuqemu>= 0 < 1:2.6+dfsg-11:2.6+dfsg-1
qemuqemu>= 0 < 1:2.6+dfsg-11:2.6+dfsg-1
qemuqemu>= 0 < 1:2.6+dfsg-11:2.6+dfsg-1
qemuqemu>= 0 < 1:2.6+dfsg-11:2.6+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.242.0.0+dfsg-2ubuntu1.24
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.11:2.5+dfsg-5ubuntu10.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.