First published: Sat Dec 10 2016(Updated: )
Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.7.1 | |
openSUSE | =42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7995 has a severity rating that indicates it can lead to denial of service due to memory consumption.
To fix CVE-2016-7995, upgrade QEMU to a version higher than 2.7.1 or apply the relevant patches if available.
CVE-2016-7995 affects QEMU versions up to and including 2.7.1 and openSUSE Leap 42.2.
CVE-2016-7995 is a memory leak vulnerability that can be exploited by local guest OS administrators.
CVE-2016-7995 cannot be exploited remotely as it requires access by local guest OS administrators.