CVE-2016-4964Infinite Loop in Qemu

CWE-835Infinite Loop7 documents6 sources
Severity
6.0MEDIUMNVD
EPSS
0.1%
top 81.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 13

Description

The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s->state.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 1.5 | Impact: 4.0

Affected Packages3 packages

debiandebian/qemu< qemu 1:2.6+dfsg-2 (bookworm)
Debianqemu/qemu< 1:2.6+dfsg-2+3
NVDqemu/qemu2.6.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wr7c-c22q-3392: The mptsas_fetch_requests function in hw/scsi/mptsas2022-05-13
OSV
CVE-2016-4964: The mptsas_fetch_requests function in hw/scsi/mptsas2016-12-10

📋Vendor Advisories

2
Red Hat
Qemu: scsi: mptsas infinite loop in mptsas_fetch_requests2016-05-24
Debian
CVE-2016-4964: qemu - The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulat...2016

💬Community

2
Bugzilla
CVE-2016-4964 Qemu: scsi: mptsas infinite loop in mptsas_fetch_requests2016-05-24
Bugzilla
CVE-2016-4964 Qemu: scsi: mptsas infinite loop in mptsas_fetch_requests [fedora-all]2016-05-24