CVE-2016-7157: Medium severity qemu vulnerability
The (1) mptsasconfigmanufacturing1 and (2) mptsasconfigioc0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSASCONFIGPACK.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7157?
CVE-2016-7157 has a high severity level due to its potential to cause a denial of service by crashing the QEMU process.
How do I fix CVE-2016-7157?
To fix CVE-2016-7157, upgrade to QEMU version 2.7.2 or later, which includes the necessary patches.
Who is affected by CVE-2016-7157?
CVE-2016-7157 affects local guest OS administrators running vulnerable versions of QEMU up to 2.7.1.
What systems are vulnerable to CVE-2016-7157?
Any system running QEMU versions 2.7.1 and earlier that utilizes the mptsas configuration functions is vulnerable to CVE-2016-7157.
What is the impact of CVE-2016-7157?
The impact of CVE-2016-7157 is that it can lead to a denial of service through crashes of the QEMU process.