CVE-2017-16845 — Improper Input Validation in Qemu
Severity
10.0CRITICALNVD
OSV4.4
EPSS
2.1%
top 16.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17
Latest updateMay 13
Description
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.8
Affected Packages4 packages
Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04