Severity
9.9CRITICAL
EPSS
1.6%
top 18.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:LExploitability: 1.3 | Impact: 3.7

Affected Packages9 packages

NVDqemu/qemu< 2.9.0
Debianqemu< 1:2.8+dfsg-4+3
CVEListV5qemu/qemu:2.9
Debianxen< 4.4.0-1+3
NVDcitrix/xenserver5 versions+4

Also affects: Debian Linux 7.0, Enterprise Linux 7.3, 7.4, 7.5

🔴Vulnerability Details

3
GHSA
GHSA-49mx-v59p-m55m: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 22022-05-13
OSV
CVE-2016-9603: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 22018-07-27
CVEList
CVE-2016-9603: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 22018-07-27

📋Vendor Advisories

4
Ubuntu
QEMU vulnerabilities2017-04-25
Ubuntu
QEMU vulnerabilities2017-04-20
Red Hat
Qemu: cirrus: heap buffer overflow via vnc connection2017-03-14
Debian
CVE-2016-9603: qemu - A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's ...2016

💬Community

3
Bugzilla
CVE-2016-9603 Qemu: cirrus: heap buffer overflow via vnc connection [fedora-all]2017-03-14
Bugzilla
CVE-2016-9603 xen: Qemu: cirrus: heap buffer overflow via vnc connection [fedora-all]2017-03-14
Bugzilla
CVE-2016-9603 Qemu: cirrus: heap buffer overflow via vnc connection2017-03-07
CVE-2016-9603 (CRITICAL CVSS 9.9) | A heap buffer overflow flaw was fou | cvebase.io