Severity
5.5MEDIUM
EPSS
0.1%
top 66.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 13

Description

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

Debianqemu< 1:2.6+dfsg-1+3
NVDqemu/qemu2.5.1+1
Debianxen< 4.4.0-1+3
NVDoracle/vm_server3.3, 3.4+1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Enterprise Linux 7.3, 7.4, 7.6, 7.7, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mfxc-vrvj-33xx: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by edi2022-05-13
CVEList
CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by edi2016-05-11
OSV
CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by edi2016-05-11

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2016-05-12
Red Hat
qemu-kvm: Out-of-bounds read when creating weird vga screen surface2016-05-09
Debian
CVE-2016-3712: qemu - Integer overflow in the VGA module in QEMU allows local guest OS users to cause ...2016

💬Community

3
Bugzilla
CVE-2016-3712 qemu: qemu-kvm: Out-of-bounds read when creating weird vga screen surface [fedora-all]2016-05-09
Bugzilla
CVE-2016-3712 xen: qemu-kvm: Out-of-bounds read when creating weird vga screen surface [fedora-all]2016-05-09
Bugzilla
CVE-2016-3712 qemu-kvm: Out-of-bounds read when creating weird vga screen surface2016-03-17
CVE-2016-3712 (MEDIUM CVSS 5.5) | Integer overflow in the VGA module | cvebase.io