Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 1 of 22
CVE-2017-5715P2MEDIUMCVSS 5.6PoCfixed in amd64-microcode 3.20180515.1 (bookworm)2017
CVE-2017-5715 [MEDIUM] CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch...
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180515.1)
bullseye: resolved (fixed in 3.20180515.1)
forky: resolved (fixed in 3.20180515.1)
sid: resolved
debian
CVE-2017-15118P2HIGHCVSS 8.3PoCfixed in qemu 1:2.11+dfsg-1 (bookworm)2017
CVE-2017-15118 [HIGH] CVE-2017-15118: qemu - A stack-based buffer overflow vulnerability was found in NBD server implementati...
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first succ
debian
CVE-2019-14378P2HIGHCVSS 8.8PoCfixed in qemu 1:4.1-1 (bookworm)2019
CVE-2019-14378 [HIGH] CVE-2019-14378: qemu - ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a ...
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
Scope: local
bookworm: resolved (fixed in 1:4.1-1)
bullseye: resolved (fixed in 1:4.1-1)
forky: resolved (fixed in 1:4.1-1)
sid: resolved (fixed in 1:4.1-1)
trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2018-12617P2LOWCVSS 7.5PoCfixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-12617 [HIGH] CVE-2018-12617: qemu - qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga ...
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to
debian
CVE-2015-3456P3HIGHCVSS 7.7PoCfixed in qemu 1:2.3+dfsg-3 (bookworm)2015
CVE-2015-3456 [HIGH] CVE-2015-3456: qemu - The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and K...
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg
debian
CVE-2017-2620P2MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-2620 [MEDIUM] CVE-2017-2620: qemu - Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator su...
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
Sco
debian
CVE-2016-9603P3MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-4 (bookworm)2016
CVE-2016-9603 [MEDIUM] CVE-2016-9603: qemu - A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's ...
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the
debian
CVE-2015-3214P3LOWCVSS 6.9PoCfixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-3214 [MEDIUM] CVE-2015-3214: linux - The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before...
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2015-7512P3CRITICALCVSS 9.0fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-7512 [CRITICAL] CVE-2015-7512: qemu - Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a ...
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.5+dfsg-1)
forky: resolved (fixed in 1:2.5+dfsg-1)
sid: r
debian
CVE-2016-7161P3CRITICALCVSS 9.8fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-7161 [CRITICAL] CVE-2016-7161: qemu - Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in ...
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
Scope: local
bookworm: resolved (fixed in 1:2.7+dfsg-1)
bullseye: resolved (fixed in 1:2.7+dfsg-1)
forky: resolved (fixed in 1:2.7+dfsg-1)
sid: resolved (fixed in 1:2.7+dfsg-1
debian
CVE-2009-3616P3MEDIUMCVSS 9.9fixed in qemu 0.11.0-1 (bookworm)2009
CVE-2009-3616 [CRITICAL] CVE-2009-3616: qemu - Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10....
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related
debian
CVE-2017-2630P3MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-2630 [MEDIUM] CVE-2017-2630: qemu - A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 b...
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with p
debian
CVE-2015-5165P3CRITICALCVSS 9.3fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5165 [CRITICAL] CVE-2015-5165: qemu - The C+ mode offload emulation in the RTL8139 network card device model in QEMU, ...
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.4+dfsg-1
debian
CVE-2021-3682P3HIGHCVSS 8.5fixed in qemu 1:6.0+dfsg-3 (bookworm)2021
CVE-2021-3682 [HIGH] CVE-2021-3682: qemu - A flaw was found in the USB redirector device emulation of QEMU in versions prio...
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with th
debian
CVE-2015-3209P3HIGHCVSS 7.5fixed in qemu 1:2.3+dfsg-6 (bookworm)2015
CVE-2015-3209 [HIGH] CVE-2015-3209: qemu - Heap-based buffer overflow in the PCNET controller in QEMU allows remote attacke...
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-6)
bullseye: resolved (fixed in 1:2.3+dfsg-6)
forky: resolved (fixed in 1:2.3+dfsg-6)
sid: resolved (fixe
debian
CVE-2017-2615P3LOWCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-2615 [MEDIUM] CVE-2017-2615: qemu - Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vu...
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU proces
debian
CVE-2016-4002P3CRITICALCVSS 9.8fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-4002 [CRITICAL] CVE-2016-4002: qemu - Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, whe...
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitrary code via a packet larger than 1514 bytes.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolved
debian
CVE-2024-24474P3HIGHCVSS 8.8fixed in qemu 1:7.2+dfsg-7+deb12u3 (bookworm)2024
CVE-2024-24474 [HIGH] CVE-2024-24474: qemu - QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a...
QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u3)
bullseye: resolved
forky: resolved (fix
debian
CVE-2016-9602P3HIGHCVSS 7.6fixed in qemu 1:2.8+dfsg-3 (bookworm)2016
CVE-2016-9602 [HIGH] CVE-2016-9602: qemu - Qemu before version 2.9 is vulnerable to an improper link following when built w...
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed in 1:2.8+dfsg-3)
forky: resolved (fix
debian
CVE-2013-4151P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4151 [HIGH] CVE-2013-4151: qemu - The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remo...
The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (
debian
1 / 22Next →