cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 19 of 22
CVE-2016-7423P4MEDIUMCVSS 4.4fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-7423 [MEDIUM] CVE-2016-7423: qemu - The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when b... The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects. Scope: local bookworm: resolved (fixed in 1:2.7+dfsg-1) bullseye: resolved (fixed in
debian
CVE-2014-0146P4MEDIUMCVSS 5.5fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0146 [MEDIUM] CVE-2014-0146: qemu - The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x befo... The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields. Scope: local bookworm: resolved (fixed in 2.0.0+dfsg-1) bullseye: resolved (fixed in 2
debian
CVE-2018-19489P4MEDIUMCVSS 4.7fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-19489 [MEDIUM] CVE-2018-19489: qemu - v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of se... v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-1) bullseye: resolved (fixed in 1:3.1+dfsg-1) forky: resolved (fixed in 1:3.1+dfsg-1) sid: resolved (fixed in 1:3.1+dfsg-1) trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2017-11334P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-11334 [MEDIUM] CVE-2017-11334: qemu - The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator)... The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed in 1:2.8+dfsg-7) for
debian
CVE-2022-0216P4MEDIUMCVSS 4.4fixed in qemu 1:7.1+dfsg-1 (bookworm)2022
CVE-2022-0216 [MEDIUM] CVE-2022-0216: qemu - A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter... A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service. Scope: local bookw
debian
CVE-2016-7170P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-7170 [MEDIUM] CVE-2016-7170: qemu - The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emula... The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bulls
debian
CVE-2012-2652P4MEDIUMCVSS 4.4fixed in qemu 1.1.0+dfsg-1 (bookworm)2012
CVE-2012-2652 [MEDIUM] CVE-2012-2652: qemu - The bdrv_open function in Qemu 1.0 does not properly handle the failure of the m... The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file. Scope: local bookworm: resolved (fixed in 1.1.0+dfsg-1) bullseye: resolved (fixed in 1.1.0+dfsg-1) forky: resolved (fixed in 1.1.0+dfs
debian
CVE-2018-20123P4LOWCVSS 5.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20123 [MEDIUM] CVE-2018-20123: qemu - pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an i... pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error. Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2016-2391P4MEDIUMCVSS 5.0fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2391 [MEDIUM] CVE-2016-2391: qemu - The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c... The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-1) bullseye: resolved (fixed in 1:2.6+dfsg-1) forky: resolved (fixed
debian
CVE-2016-5238P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3 (bookworm)2016
CVE-2016-5238 [MEDIUM] CVE-2016-5238: qemu - The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS adminis... The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-3) bullseye: resolved (fixed in 1:2.6+dfsg-3) forky: resolved (fixed in
debian
CVE-2016-7908P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-7908 [MEDIUM] CVE-2016-7908: qemu - The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does... The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags. Scope: local
debian
CVE-2016-7907P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-3 (bookworm)2016
CVE-2016-7907 [MEDIUM] CVE-2016-7907: qemu - The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does... The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags. Scope: local
debian
CVE-2020-35505P4MEDIUMCVSS 4.4fixed in qemu 1:6.0+dfsg-3 (bookworm)2020
CVE-2020-35505 [MEDIUM] CVE-2020-35505: qemu - A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter ... A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availa
debian
CVE-2020-13361P4LOWCVSS 3.9fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13361 [LOW] CVE-2020-13361: qemu - In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not p... In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation. Scope: local bookworm: resolved (fixed in 1:5.0-6) bullseye: resolved (fixed in 1:5.0-6) forky: resolved (fixed in 1:5.0-6) sid: resolved (fixed in 1:5.0-6) tr
debian
CVE-2020-16092P4LOWCVSS 3.8fixed in qemu 1:5.1+dfsg-1 (bookworm)2020
CVE-2020-16092 [LOW] CVE-2020-16092: qemu - In QEMU through 5.0.0, an assertion failure can occur in the network packet proc... In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c. Scope: local bookworm: resolved (fixe
debian
CVE-2021-3592P4LOWCVSS 3.8fixed in libslirp 4.6.1-1 (bookworm)2021
CVE-2021-3592 [LOW] CVE-2021-3592: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem... An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from
debian
CVE-2021-3594P4LOWCVSS 3.8fixed in libslirp 4.6.1-1 (bookworm)2021
CVE-2021-3594 [LOW] CVE-2021-3594: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem... An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from thi
debian
CVE-2021-3595P4LOWCVSS 3.8fixed in libslirp 4.6.1-1 (bookworm)2021
CVE-2021-3595 [LOW] CVE-2021-3595: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem... An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from th
debian
CVE-2021-3593P4LOWCVSS 3.8fixed in libslirp 4.6.1-1 (bookworm)2021
CVE-2021-3593 [LOW] CVE-2021-3593: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem... An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from th
debian
CVE-2015-4105P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4105 [MEDIUM] CVE-2015-4105: qemu - Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error message... Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of service (host disk consumption) via certain invalid operations. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3+dfsg-5) forky: resolved (fixed in 1:2.3+dfsg-5) sid: resolved (fixed in 1:2.3+
debian
Debian Qemu vulnerabilities | cvebase