Severity
6.0MEDIUMNVD
EPSS
0.1%
top 73.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 13

Description

Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 1.5 | Impact: 4.0

Affected Packages5 packages

Debianqemu/qemu< 1:2.7+dfsg-1+3
NVDqemu/qemu2.7.1
NVDopensuse/leap42.2
NVDredhat/openstack6 versions+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6xqp-cpj7-9325: Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci2022-05-13
OSV
CVE-2016-7466: Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci2016-12-10
CVEList
CVE-2016-7466: Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci2016-12-10

📋Vendor Advisories

4
Red Hat
ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587)2017-04-11
Ubuntu
QEMU vulnerabilities2016-11-09
Red Hat
Qemu: usb: xhci memory leakage during device unplug2016-09-13
Debian
CVE-2016-7466: qemu - Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quic...2016

💬Community

3
Bugzilla
CVE-2017-7466 ansible1.9: ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [epel-all]2017-04-11
Bugzilla
CVE-2016-7466 Qemu: usb: xhci memory leakage during device unplug2016-09-20
Bugzilla
CVE-2016-7466 Qemu: usb: xhci memory leakage during device unplug [fedora-all]2016-09-20
CVE-2016-7466 — Qemu vulnerability | cvebase