First published: Sat Dec 10 2016(Updated: )
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.7.1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7155 is classified as a high severity vulnerability due to its ability to cause a denial of service.
To fix CVE-2016-7155, update QEMU to version 2.7.2 or later.
CVE-2016-7155 affects QEMU versions up to and including 2.7.1.
CVE-2016-7155 can lead to out-of-bounds access or an infinite loop, resulting in the crash of the QEMU process.
Systems running vulnerable versions of QEMU, particularly on Debian Linux 8.0 and below, are susceptible to CVE-2016-7155.