cbcvebase.
CVE-2016-7161
published 2016-10-05

CVE-2016-7161: Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the…

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.06%
92.6th percentile
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianqemu< qemu 1:2.7+dfsg-1 (bookworm)qemu 1:2.7+dfsg-1 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_qemu-kvm_4.2.0-12_on_cbl_mariner_1.0
qemuqemu<= 2.6.2
qemuqemu
qemuqemu>= 0 < 1:2.7+dfsg-11:2.7+dfsg-1
qemuqemu>= 0 < 1:2.7+dfsg-11:2.7+dfsg-1
qemuqemu>= 0 < 1:2.7+dfsg-11:2.7+dfsg-1
qemuqemu>= 0 < 1:2.7+dfsg-11:2.7+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.302.0.0+dfsg-2ubuntu1.30
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.61:2.5+dfsg-5ubuntu10.6

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via a large ethlite packet sent to the xlnx.xps-ethernetlite virtual NIC in QEMU; monitor for oversized packets targeting this device model as a potential exploitation indicator.
  • The root cause is the absence of a length check before memcpy in the .receive callback of xlnx.xps-ethernetlite; detection logic should flag any guest-to-host network path through this device where packet length is not validated.
  • The upstream fix commit can be used as a patch-level detection reference to verify whether a QEMU binary has been patched against this vulnerability.
  • ·All versions of QEMU that include the xlnx.xps-ethernetlite device model are affected; exploitation requires the guest to be configured with this specific virtual NIC.
  • ·Red Hat Enterprise Linux 6 and 7 qemu-kvm packages were assessed as not affected, suggesting their builds do not expose the vulnerable device model.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.