CVE-2016-1981: Medium severity qemu vulnerability
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instance resulting in DoS.
— Launchpad
Qemu emulator built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head(TDH/RDH) is set outside the allocated descriptor buffer.
A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS.
Upstream patch -------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg03454.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/01/22/1
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-1981?
CVE-2016-1981 is a vulnerability in QEMU (aka Quick Emulator) that is caused by an infinite loop issue.
How does CVE-2016-1981 occur?
CVE-2016-1981 occurs while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer.
What is the severity of CVE-2016-1981?
CVE-2016-1981 has a low severity.
Which software is affected by CVE-2016-1981?
QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, 1.0+, and qemu versions 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u10, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u1, 1:8.0.4+dfsg-3, 1:8.1.0+ds-6 are affected by CVE-2016-1981.
How can I fix CVE-2016-1981?
To fix CVE-2016-1981, update QEMU to a version that includes the necessary security patches. For Ubuntu, version 2.0.0+dfsg-2ubuntu1.22 or higher contains the fix. For Debian, please refer to the Debian security advisories for the specific versions that include the fix.