CVE-2016-8668
published 2016-11-04CVE-2016-8668: The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…
PriorityP418medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.39%
32.0th percentile
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.8+dfsg-1 (bookworm) | qemu 1:2.8+dfsg-1 (bookworm) |
| opensuse | leap | — | — |
| qemu | qemu | <= 2.7.1 | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-1 | 1:2.8+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-1 | 1:2.8+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-1 | 1:2.8+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-1 | 1:2.8+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.30 | 2.0.0+dfsg-2ubuntu1.30 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.6 | 1:2.5+dfsg-5ubuntu10.6 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-11-09·CVSS 5.5
CVE-2016-5403 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A
privileged attacker inside the guest could use this issue to cause QEMU to
consume resources, resulting in a denial of service. (CVE-2016-5403)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-6833, CVE-2016-6834, CVE-2016-6888)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue
Red Hat
Qemu: net: OOB buffer access in rocker switch emulation
vendor_redhat·2016-10-12·CVSS 6.0
CVE-2016-8668 [MEDIUM] CWE-125 Qemu: net: OOB buffer access in rocker switch emulation
Qemu: net: OOB buffer access in rocker switch emulation
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affecte
Debian
CVE-2016-8668: qemu - The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emula...
vendor_debian·2016·CVSS 6.0
CVE-2016-8668 [MEDIUM] CVE-2016-8668: qemu - The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emula...
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fixed in 1:2.8+dfsg-1)
sid: resolved (fixed in 1:2.8+dfsg-1)
trixie: resolved (fixed in 1:2.8+dfsg-1)
GHSA
GHSA-h48h-v2qr-c72q: The rocker_io_writel function in hw/net/rocker/rocker
ghsa_unreviewed·2022-05-13
CVE-2016-8668 [MEDIUM] CWE-120 GHSA-h48h-v2qr-c72q: The rocker_io_writel function in hw/net/rocker/rocker
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-11-09·CVSS 5.5
CVE-2016-5403 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A
privileged attacker inside the guest could use this issue to cause QEMU to
consume resources, resulting in a denial of service. (CVE-2016-5403)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-6833, CVE-2016-6834, CVE-2016-6888)
Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network
card emulation support. A privileged attacker inside the guest could use
this issue to cause QEMU to crash, resulting in a denial of se
OSV
CVE-2016-8668: The rocker_io_writel function in hw/net/rocker/rocker
osv·2016-11-04·CVSS 6.0
CVE-2016-8668 [MEDIUM] CVE-2016-8668: The rocker_io_writel function in hw/net/rocker/rocker
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation [fedora-all]
bugzilla·2016-10-14·CVSS 6.0
CVE-2016-8668 [MEDIUM] CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation [fedora-all]
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
bugzilla·2016-10-14·CVSS 6.0
CVE-2016-8668 [MEDIUM] CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
Quick Emulator(Qemu) built with the Rocker switch emulation support is
vulnerable to an OOB read access issue. It could occur while performing a DMA
access 'TEST_DMA_CTRL_INVERT' test.
A privileged guest user could use this issue to crash the Qemu process instance
on the host resulting in DoS.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg02501.html
Discussion:
Acknowledgments:
Name: PSIRT (Huawei Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1384898]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q4/141
---
commit 8caed3d564672e8bc6d2e4c6a35228afd01f4723
Author: Prasad J Pandit
Date: Wed Oct 12 14:40:55 2016 +0530
net: rocker: set limit t
Bugzilla
CVE-2015-8668 libtiff: OOB read in bmp2tiff
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-8668 [CRITICAL] CVE-2015-8668 libtiff: OOB read in bmp2tiff
CVE-2015-8668 libtiff: OOB read in bmp2tiff
A heap-buffer oveflow was found in bmp2tiff, A tool used to created TIFF format files from BMP format image files. An attacker could provide a specially-crafted BMP format file, which when converted to TIFF format, using the bmp2tiff tool, could lead to bmp2tiff executable to crash.
Reference:
http://seclists.org/bugtraq/2015/Dec/138
Discussion:
I haven't completed my analysis yet, but for now I tend to say that this is only OOB read.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-
http://lists.opensuse.org/opensuse-updates/2016-12/msg00140.htmlhttp://www.openwall.com/lists/oss-security/2016/10/14/8http://www.openwall.com/lists/oss-security/2016/10/15/9http://www.securityfocus.com/bid/93566https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg02501.htmlhttps://security.gentoo.org/glsa/201611-11http://lists.opensuse.org/opensuse-updates/2016-12/msg00140.htmlhttp://www.openwall.com/lists/oss-security/2016/10/14/8http://www.openwall.com/lists/oss-security/2016/10/15/9http://www.securityfocus.com/bid/93566https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg02501.htmlhttps://security.gentoo.org/glsa/201611-11
2016-11-04
Published