cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 12 of 22
CVE-2016-9921P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9921 [MEDIUM] CVE-2016-9921: qemu - Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vu... Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1)
debian
CVE-2017-5856P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5856 [MEDIUM] CVE-2017-5856: qemu - Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (ak... Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-3) bullseye: resolved (fixed in
debian
CVE-2017-5857P4LOWCVSS 6.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5857 [MEDIUM] CVE-2017-5857: qemu - Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d... Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage beforehand. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-3) bull
debian
CVE-2014-7815P4MEDIUMCVSS 5.0fixed in qemu 2.1+dfsg-7 (bookworm)2014
CVE-2014-7815 [MEDIUM] CVE-2014-7815: qemu - The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cau... The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. Scope: local bookworm: resolved (fixed in 2.1+dfsg-7) bullseye: resolved (fixed in 2.1+dfsg-7) forky: resolved (fixed in 2.1+dfsg-7) sid: resolved (fixed in 2.1+dfsg-7) trixie: resolved (fixed in 2.1+dfsg-7)
debian
CVE-2014-0147P4MEDIUMCVSS 6.2fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0147 [MEDIUM] CVE-2014-0147: qemu - Qemu before 1.6.2 block diver for the various disk image formats used by Bochs a... Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine. Scope: local bookworm: resolved (fixed in 2.0.0+dfsg-1) bullseye: resolved (fixed i
debian
CVE-2017-15289P4MEDIUMCVSS 6.0fixed in qemu 1:2.11+dfsg-1 (bookworm)2017
CVE-2017-15289 [MEDIUM] CVE-2017-15289: qemu - The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS ... The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation. Scope: local bookworm: resolved (fixed in 1:2.11+dfsg-1) bullseye: resolved (fixed in 1:2.11+dfsg-1) forky: resolved (fixed in 1:2.11+dfsg-1) sid
debian
CVE-2021-3416P4MEDIUMCVSS 6.0fixed in qemu 1:5.2+dfsg-9 (bookworm)2021
CVE-2021-3416 [MEDIUM] CVE-2021-3416: qemu - A potential stack overflow via infinite loop issue was found in various NIC emul... A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario. Scope: local bookworm: res
debian
CVE-2016-4454P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-3 (bookworm)2016
CVE-2016-4454 [MEDIUM] CVE-2016-4454: qemu - The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows loca... The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-3) bullseye: resolved (fix
debian
CVE-2021-3608P4MEDIUMCVSS 6.0fixed in qemu 1:5.2+dfsg-11 (bookworm)2021
CVE-2021-3608 [MEDIUM] CVE-2021-3608: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device ... A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability. Scope: l
debian
CVE-2019-15034P4MEDIUMCVSS 5.8fixed in qemu 1:4.1-1 (bookworm)2019
CVE-2019-15034 [MEDIUM] CVE-2019-15034: qemu - hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config... hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space. Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2020-10717P4LOWCVSS 3.3fixed in qemu 1:5.0-5 (bookworm)2020
CVE-2020-10717 [LOW] CVE-2020-10717: qemu - A potential DoS flaw was found in the virtio-fs shared file system daemon (virti... A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest via virtio-fs device. If the guest opens the maximum number of file descriptors under the shared directory, a denial of service may occur. This flaw allows a guest user/pro
debian
CVE-2019-6501P4MEDIUMCVSS 5.5fixed in qemu 1:3.1+dfsg-3 (bookworm)2019
CVE-2019-6501 [MEDIUM] CVE-2019-6501: qemu - In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-b... In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-3) bullseye: resolved (fixed in 1:3.1+dfsg-3) forky: resolved (fixed in 1:3.1+dfsg-3) sid: resolved (fixed in 1:3.1+dfsg-3) trixie: resolved (fixed in 1:3.1+dfsg-3)
debian
CVE-2017-15038P4MEDIUMCVSS 5.6fixed in qemu 1:2.10.0+dfsg-2 (bookworm)2017
CVE-2017-15038 [MEDIUM] CVE-2017-15038: qemu - Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick... Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes. Scope: local bookworm: resolved (fixed in 1:2.10.0+dfsg-2) bullseye: resolved (fixed in 1:2.10.0+dfsg-2) forky: resolved (fixed in 1:2.10.0+dfsg
debian
CVE-2019-9824P4MEDIUMCVSS 5.5fixed in qemu 1:3.1+dfsg-6 (bookworm)2019
CVE-2019-9824 [MEDIUM] CVE-2019-9824: qemu - tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninit... tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-6) bullseye: resolved (fixed in 1:3.1+dfsg-6) forky: resolved (fixed in 1:3.1+dfsg-6) sid: resolved (fixed in 1:3.1+dfsg-6) trixie: resolved (fixed in 1:3.1+dfsg-6)
debian
CVE-2015-5158P4MEDIUMCVSS 5.5fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5158 [MEDIUM] CVE-2015-5158: qemu - Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-... Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky:
debian
CVE-2020-24352P4LOWCVSS 5.5fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-24352 [MEDIUM] CVE-2020-24352: qemu - An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access wa... An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of
debian
CVE-2015-8817P4MEDIUMCVSS 5.5fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-8817 [MEDIUM] CVE-2015-8817: qemu - QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an addre... QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS. Scope: local bookworm: res
debian
CVE-2020-13791P4MEDIUMCVSS 5.5fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13791 [MEDIUM] CVE-2020-13791: qemu - hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds acc... hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space. Scope: local bookworm: resolved (fixed in 1:5.0-6) bullseye: resolved (fixed in 1:5.0-6) forky: resolved (fixed in 1:5.0-6) sid: resolved (fixed in 1:5.0-6) trixie: resolved (fixed in 1:5.0-6)
debian
CVE-2021-3527P4MEDIUMCVSS 5.5fixed in qemu 1:5.2+dfsg-11 (bookworm)2021
CVE-2021-3527 [MEDIUM] CVE-2021-3527: qemu - A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB pac... A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded, a malici
debian
CVE-2020-25085P4MEDIUMCVSS 5.0fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-25085 [MEDIUM] CVE-2020-25085: qemu - QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c ... QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+df
debian
Debian Qemu vulnerabilities | cvebase