First published: Sat Dec 10 2016(Updated: )
The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSAS_CONFIG_PACK.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7157 has a high severity level due to its potential to cause a denial of service by crashing the QEMU process.
To fix CVE-2016-7157, upgrade to QEMU version 2.7.2 or later, which includes the necessary patches.
CVE-2016-7157 affects local guest OS administrators running vulnerable versions of QEMU up to 2.7.1.
Any system running QEMU versions 2.7.1 and earlier that utilizes the mptsas configuration functions is vulnerable to CVE-2016-7157.
The impact of CVE-2016-7157 is that it can lead to a denial of service through crashes of the QEMU process.