CVE-2016-6836: Medium severity qemu vulnerability
Published Dec 10, 2016
·Updated
The vmxnet3completepacket function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcqdescr object.
Affected Software
2 affected components
Qemu Qemu<=2.7.1
Debian Debian Linux=8.0
Remediation
Event History
Dec 10, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6836?
CVE-2016-6836 is rated as a medium severity vulnerability due to its potential impact on host memory information exposure.
2
How do I fix CVE-2016-6836?
To fix CVE-2016-6836, upgrade QEMU to version 2.7.2 or later.
3
Who is affected by CVE-2016-6836?
CVE-2016-6836 affects local guest OS administrators using vulnerable versions of QEMU and Debian Linux 8.0.
4
What type of attack does CVE-2016-6836 enable?
CVE-2016-6836 allows local guest OS administrators to leak sensitive host memory information.
5
When was CVE-2016-6836 disclosed?
CVE-2016-6836 was disclosed in August 2016, highlighting a significant security weakness in QEMU.