CVE-2016-3712: Integer Overflow
Published May 11, 2016
·Updated
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
Affected Software
32 affected components
Oracle VM Server=3.3
Oracle VM Server=3.4
Qemu Qemu<=2.5.1
Qemu Qemu=2.6.0-rc0
Qemu Qemu=2.6.0-rc1
Qemu Qemu=2.6.0-rc2
Qemu Qemu=2.6.0-rc3
Qemu Qemu=2.6.0-rc4
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Debian Debian Linux=8.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Eus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Citrix XenServer<=7.0
Remediation
Event History
May 11, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3712?
CVE-2016-3712 has a high severity due to its potential to cause a denial of service.
2
How do I fix CVE-2016-3712?
To fix CVE-2016-3712, update QEMU to version 2.6.0 or later, and apply all relevant patches for Oracle VM Server and affected Linux distributions.
3
Which software is affected by CVE-2016-3712?
CVE-2016-3712 affects several versions of QEMU, Oracle VM Server 3.3 and 3.4, and specific releases of Ubuntu and Red Hat Enterprise Linux.
4
Can CVE-2016-3712 be exploited remotely?
No, CVE-2016-3712 requires local access to the guest OS to exploit the vulnerability.
5
What is the type of vulnerability for CVE-2016-3712?
CVE-2016-3712 is categorized as an integer overflow vulnerability within the VGA module of QEMU.