CVE-2016-2857: Buffer Overflow
Published Apr 8, 2016
·Updated
The netchecksumcalculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
Affected Software
33 affected components
Qemu Qemu<=2.5.1.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Debian Debian Linux=8.0
redhat Openstack=5.0
redhat Virtualization=3.0
redhat Virtualization=4.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=6.0
redhat Openstack=6.0
redhat Openstack=7.0
redhat Openstack=8
redhat Openstack=9
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Event History
Apr 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2857?
CVE-2016-2857 is classified as a medium severity vulnerability due to its potential for denial of service through an out-of-bounds heap read.
2
How do I fix CVE-2016-2857?
To fix CVE-2016-2857, users should upgrade QEMU to version 2.5.1.2 or later.
3
Who is affected by CVE-2016-2857?
CVE-2016-2857 affects local guest OS users on specific versions of QEMU and several distributions like Ubuntu and Debian.
4
What type of vulnerability is CVE-2016-2857?
CVE-2016-2857 is an out-of-bounds read vulnerability that can lead to denial of service.
5
Can CVE-2016-2857 be exploited remotely?
No, CVE-2016-2857 requires local access to the guest OS to exploit the vulnerability.