CVE-2016-7422
published 2016-12-10CVE-2016-7422: The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL…
PriorityP417medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.36%
29.0th percentile
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.7+dfsg-1 (bookworm) | qemu 1:2.7+dfsg-1 (bookworm) |
| opensuse | leap | — | — |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.1 | 5.18.2-2ubuntu1.1 |
| qemu | qemu | <= 2.7.1 | — |
| qemu | qemu | >= 0 < 1:2.7+dfsg-1 | 1:2.7+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.7+dfsg-1 | 1:2.7+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.7+dfsg-1 | 1:2.7+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.7+dfsg-1 | 1:2.7+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.30 | 2.0.0+dfsg-2ubuntu1.30 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.6 | 1:2.5+dfsg-5ubuntu10.6 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-11-09·CVSS 5.5
CVE-2016-5403 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A
privileged attacker inside the guest could use this issue to cause QEMU to
consume resources, resulting in a denial of service. (CVE-2016-5403)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-6833, CVE-2016-6834, CVE-2016-6888)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue
Red Hat
Qemu: virtio: null pointer dereference in virtqueu_map_desc
vendor_redhat·2016-09-15·CVSS 6.0
CVE-2016-7422 [MEDIUM] CWE-476 Qemu: virtio: null pointer dereference in virtqueu_map_desc
Qemu: virtio: null pointer dereference in virtqueu_map_desc
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Debian
CVE-2016-7422: qemu - The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulato...
vendor_debian·2016·CVSS 6.0
CVE-2016-7422 [MEDIUM] CVE-2016-7422: qemu - The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulato...
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
Scope: local
bookworm: resolved (fixed in 1:2.7+dfsg-1)
bullseye: resolved (fixed in 1:2.7+dfsg-1)
forky: resolved (fixed in 1:2.7+dfsg-1)
sid: resolved (fixed in 1:2.7+dfsg-1)
trixie: resolved (fixed in 1:2.7+dfsg-1)
GHSA
GHSA-fp4p-m87h-5fx8: The virtqueue_map_desc function in hw/virtio/virtio
ghsa_unreviewed·2022-05-13
CVE-2016-7422 [MEDIUM] CWE-120 GHSA-fp4p-m87h-5fx8: The virtqueue_map_desc function in hw/virtio/virtio
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
OSV
CVE-2016-7422: The virtqueue_map_desc function in hw/virtio/virtio
osv·2016-12-10·CVSS 6.0
CVE-2016-7422 [MEDIUM] CVE-2016-7422: The virtqueue_map_desc function in hw/virtio/virtio
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-11-09·CVSS 5.5
CVE-2016-5403 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A
privileged attacker inside the guest could use this issue to cause QEMU to
consume resources, resulting in a denial of service. (CVE-2016-5403)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-6833, CVE-2016-6834, CVE-2016-6888)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of se
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc
bugzilla·2016-09-16·CVSS 6.0
CVE-2016-7422 [MEDIUM] CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc
CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc
Quick emulator(Qemu) built with the virtio framework is vulnerable to a null
pointer dereference flaw. It could occur if the guest was to set the I/O
descriptor buffer length to a large value.
A privileged user inside guest could use this flaw to crash the Qemu instance
on the host resulting in DoS.
Upstream fix:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03546.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/09/16/4
Discussion:
Acknowledgments:
Name: Qinghao Tang (360.cn Marvel Team), Zhenhao Hong (360.cn Marvel Team)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1376756]
---
This issue has been addressed in the following products:
Red Hat Ope
Bugzilla
CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc [fedora-all]
bugzilla·2016-09-16·CVSS 6.0
CVE-2016-7422 [MEDIUM] CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc [fedora-all]
CVE-2016-7422 Qemu: virtio: null pointer dereference in virtqueu_map_desc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=973e7170dddefb491a48df5cba33b2ae151013a0http://lists.opensuse.org/opensuse-updates/2016-12/msg00140.htmlhttp://www.openwall.com/lists/oss-security/2016/09/16/10http://www.openwall.com/lists/oss-security/2016/09/16/4http://www.securityfocus.com/bid/92996https://access.redhat.com/errata/RHSA-2017:2392https://access.redhat.com/errata/RHSA-2017:2408https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03546.htmlhttps://security.gentoo.org/glsa/201609-01http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=973e7170dddefb491a48df5cba33b2ae151013a0http://lists.opensuse.org/opensuse-updates/2016-12/msg00140.htmlhttp://www.openwall.com/lists/oss-security/2016/09/16/10http://www.openwall.com/lists/oss-security/2016/09/16/4http://www.securityfocus.com/bid/92996https://access.redhat.com/errata/RHSA-2017:2392https://access.redhat.com/errata/RHSA-2017:2408https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03546.htmlhttps://security.gentoo.org/glsa/201609-01
2016-12-10
Published