cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 17 of 22
CVE-2016-8668P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8668 [MEDIUM] CVE-2016-8668: qemu - The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emula... The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved (fixed in 1:2
debian
CVE-2016-7995P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-7995 [MEDIUM] CVE-2016-7995: qemu - Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Q... Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved (fixed in 1
debian
CVE-2016-9106P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9106 [MEDIUM] CVE-2016-9106: qemu - Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulat... Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved (fixed in 1:2.8+dfsg-1) sid: resolved (fi
debian
CVE-2016-6835P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6835 [MEDIUM] CVE-2016-6835: qemu - The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka ... The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-3.1) bullseye: resolved (fixed in 1:2.6+dfsg-3.1) forky: resolved (fixed in 1:2.6+dfsg-3
debian
CVE-2016-4964P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-4964 [MEDIUM] CVE-2016-4964: qemu - The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulat... The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s->state. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-2) bullseye: resolved (fixed in 1:2.6+dfsg-2) forky: resolved (fixed in 1:2.6
debian
CVE-2017-7377P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-4 (bookworm)2017
CVE-2017-7377 [MEDIUM] CVE-2017-7377: qemu - The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka ... The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-4) bullseye: resolved (fixed in 1:2.8+dfsg-4) forky: resolved (fixed
debian
CVE-2016-9102P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9102 [MEDIUM] CVE-2016-9102: qemu - Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick ... Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) fo
debian
CVE-2016-4952P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-4952 [MEDIUM] CVE-2016-4952: qemu - QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus em... QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-2) bullseye: resolved (fi
debian
CVE-2020-28916P4MEDIUMCVSS 5.5fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-28916 [MEDIUM] CVE-2020-28916: qemu - hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor wit... hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+dfsg-1)
debian
CVE-2017-9310P4MEDIUMCVSS 5.6fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-9310 [MEDIUM] CVE-2017-9310: qemu - QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, all... QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed
debian
CVE-2016-3712P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-3712 [MEDIUM] CVE-2016-3712: qemu - Integer overflow in the VGA module in QEMU allows local guest OS users to cause ... Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-1) bullseye: resolved (fixed in 1:2.6+dfsg-1) forky: resolved (fixed in 1:2.6+dfsg-1) sid: resolved (fixed in 1:2.6+dfsg-1) trixie: reso
debian
CVE-2018-15746P4LOWCVSS 5.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-15746 [MEDIUM] CVE-2018-15746: qemu - qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of ser... qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-1) bullseye: resolved (fixed in 1:3.1+dfsg-1) forky: resolved (fixed in 1:3.1+dfsg-1) sid: resolved (fixed in 1:3.1+dfsg-1) trixi
debian
CVE-2015-8558P4MEDIUMCVSS 5.5fixed in qemu 1:2.5+dfsg-2 (bookworm)2015
CVE-2015-8558 [MEDIUM] CVE-2015-8558: qemu - The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS... The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list. Scope: local bookworm: resolved (fixed in 1:2.5+dfsg-2) bullseye: resolved (fixed in 1:2.5+dfsg-2) forky: resolved (fixed in 1:2.5+dfsg-2) sid: resolve
debian
CVE-2017-5973P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5973 [MEDIUM] CVE-2017-5973: qemu - The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) a... The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-3) bullseye: resolved (fixed in 1:2.8+dfsg-3) forky: resolved (fixed in
debian
CVE-2017-9374P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-9374 [MEDIUM] CVE-2017-9374: qemu - Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation sup... Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed in 1:2.8+dfsg-7) forky: resolved (fixed in 1:2.8+dfsg-7) sid: resolved (f
debian
CVE-2017-9373P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-9373 [MEDIUM] CVE-2017-9373: qemu - Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation sup... Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed in 1:2.8+dfsg-7) forky: resolved (fixed in 1:2.8+dfsg-7) sid: resolv
debian
CVE-2015-8818P4MEDIUMCVSS 5.5fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-8818 [MEDIUM] CVE-2015-8818: qemu - The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick... The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky: resolved (fixed in 1:2.4+
debian
CVE-2017-11434P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-11434 [MEDIUM] CVE-2017-11434: qemu - The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows lo... The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed in 1:2.8+dfsg-7) forky: resolved (fixed in 1:2.8+dfsg-7) sid: resolved (fixed in
debian
CVE-2023-40360P4LOWCVSS 5.5fixed in qemu 1:8.0.4+dfsg-2 (forky)2023
CVE-2023-40360 [MEDIUM] CVE-2023-40360: qemu - QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/... QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:8.0.4+dfsg-2) sid: resolved (fixed in 1:8.0.4+dfsg-2) trixie: resolved (
debian
CVE-2016-5105P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5105 [MEDIUM] CVE-2016-5105: qemu - The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with... The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-2) bullseye: resolved
debian
Debian Qemu vulnerabilities | cvebase