CVE-2016-7909: Medium severity qemu vulnerability
Published Oct 5, 2016
·Updated
The pcnetrdraaddr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
Affected Software
2 affected components
Qemu Qemu<=2.7.1
Debian Debian Linux=8.0
Remediation
Event History
Oct 5, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7909?
CVE-2016-7909 has been classified as a denial of service vulnerability.
2
How can I mitigate CVE-2016-7909?
To mitigate CVE-2016-7909, ensure that the receive and transmit descriptor ring lengths are not set to 0.
3
Which versions of QEMU are affected by CVE-2016-7909?
CVE-2016-7909 affects QEMU versions up to and including 2.7.1.
4
What is the impact of CVE-2016-7909 on a system?
The impact of CVE-2016-7909 includes causing an infinite loop and crashing the QEMU process.
5
Is CVE-2016-7909 specific to certain operating systems?
Yes, CVE-2016-7909 is also noted to affect Debian GNU/Linux version 8.0.