CVE-2016-3710

CWE-119Buffer Overflow10 documents8 sources
Severity
8.8HIGH
EPSS
0.1%
top 77.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 13

Description

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages12 packages

Debianqemu< 1:2.6+dfsg-1+3
NVDqemu/qemu2.5.1+1
Debianxen< 4.4.0-1+3
NVDoracle/linux5, 6, 7+2

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Enterprise Linux 7.2, 7.3, 7.4, 7.6, 7.5, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p6hq-65m2-r4jg: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arb2022-05-13
CVEList
CVE-2016-3710: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arb2016-05-11
OSV
CVE-2016-3710: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arb2016-05-11

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2016-05-12
Red Hat
qemu: incorrect banked access bounds checking in vga module2016-05-09
Debian
CVE-2016-3710: qemu - The VGA module in QEMU improperly performs bounds checking on banked access to v...2016

💬Community

3
Bugzilla
CVE-2016-3710 xen: qemu: incorrect banked access bounds checking in vga module [fedora-all]2016-05-09
Bugzilla
CVE-2016-3710 qemu: incorrect banked access bounds checking in vga module [fedora-all]2016-05-09
Bugzilla
CVE-2016-3710 qemu: incorrect banked access bounds checking in vga module2016-04-28
CVE-2016-3710 (HIGH CVSS 8.8) | The VGA module in QEMU improperly p | cvebase.io