CVE-2016-6490Classic Buffer Overflow in Qemu

Severity
4.4MEDIUMNVD
EPSS
0.1%
top 77.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 13

Description

The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/qemu< qemu 1:2.6+dfsg-3.1 (bookworm)
Debianqemu/qemu< 1:2.6+dfsg-3.1+3
NVDqemu/qemu2.6.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-683h-m32r-vcgg: The virtqueue_map_desc function in hw/virtio/virtio2022-05-13
OSV
CVE-2016-6490: The virtqueue_map_desc function in hw/virtio/virtio2016-12-10

📋Vendor Advisories

2
Red Hat
Qemu: virtio: infinite loop in virtqueue_pop2016-07-27
Debian
CVE-2016-6490: qemu - The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulato...2016

💬Community

2
Bugzilla
CVE-2016-6490 Qemu: virtio: infinite loop in virtqueue_pop [fedora-all]2016-07-29
Bugzilla
CVE-2016-6490 Qemu: virtio: infinite loop in virtqueue_pop2016-07-29