CVE-2016-7421: Medium severity qemu vulnerability
Published Dec 10, 2016
·Updated
The pvscsiringpopreqdescr function in hw/scsi/vmwpvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
Affected Software
2 affected components
Qemu Qemu<=2.7.1
Debian Debian Linux=8.0
Remediation
Event History
Dec 10, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7421?
CVE-2016-7421 is classified as a denial of service vulnerability.
2
How can I fix CVE-2016-7421?
To fix CVE-2016-7421, upgrade QEMU to a version above 2.7.1 or apply relevant patches.
3
Who is affected by CVE-2016-7421?
CVE-2016-7421 affects local guest OS administrators using vulnerable versions of QEMU.
4
What causes the vulnerability CVE-2016-7421?
CVE-2016-7421 is caused by the pvscsi_ring_pop_req_descr function failing to limit the IO loop to the ring size.
5
What are the potential consequences of exploiting CVE-2016-7421?
Exploiting CVE-2016-7421 can lead to an infinite loop and crash of the QEMU process.