CVE-2016-2858
published 2016-04-07CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via…
PriorityP426medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.39%
32.0th percentile
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.6+dfsg-1 (bookworm) | qemu 1:2.6+dfsg-1 (bookworm) |
| qemu | qemu | <= 2.5.1.1 | — |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-1 | 1:2.6+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.24 | 2.0.0+dfsg-2ubuntu1.24 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.1 | 1:2.5+dfsg-5ubuntu10.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m22w-qpwr-jxrj: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process cr
ghsa_unreviewed·2022-05-13
CVE-2016-2858 [MEDIUM] CWE-331 GHSA-m22w-qpwr-jxrj: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process cr
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU incorrectly handled NE2000 emulation
support. A priv
OSV
CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process cr
osv·2016-04-07·CVSS 6.5
CVE-2016-2858 [MEDIUM] CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process cr
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU i
Red Hat
Qemu: rng-random: arbitrary stack based allocation leading to corruption
vendor_redhat·2016-01-22·CVSS 6.5
CVE-2016-2858 [MEDIUM] Qemu: rng-random: arbitrary stack based allocation leading to corruption
Qemu: rng-random: arbitrary stack based allocation leading to corruption
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Statement: This has been rated as having Low security impact and is not currently
planned to be addressed in future updates. For additional information, refer
to the Red Hat Enterprise Linux Life Cycle:
https://access.redhat.com/support/policy/updates/errata/.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Will not fix
Package: qemu-kvm (Red Hat Enterpr
Debian
CVE-2016-2858: qemu - QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support...
vendor_debian·2016·CVSS 6.5
CVE-2016-2858 [MEDIUM] CVE-2016-2858: qemu - QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support...
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolved (fixed in 1:2.6+dfsg-1)
sid: resolved (fixed in 1:2.6+dfsg-1)
trixie: resolved (fixed in 1:2.6+dfsg-1)
No detection rules found.
No public exploits indexed.
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=60253ed1e6ec6d8e5ef2efe7bf755f475dce9956http://www.openwall.com/lists/oss-security/2016/03/04/1http://www.openwall.com/lists/oss-security/2016/03/07/4http://www.securityfocus.com/bid/84134http://www.ubuntu.com/usn/USN-2974-1https://bugzilla.redhat.com/show_bug.cgi?id=1314676https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://security.gentoo.org/glsa/201604-01http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=60253ed1e6ec6d8e5ef2efe7bf755f475dce9956http://www.openwall.com/lists/oss-security/2016/03/04/1http://www.openwall.com/lists/oss-security/2016/03/07/4http://www.securityfocus.com/bid/84134http://www.ubuntu.com/usn/USN-2974-1https://bugzilla.redhat.com/show_bug.cgi?id=1314676https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://security.gentoo.org/glsa/201604-01
2016-04-07
Published