CVE-2016-7995: Medium severity qemu vulnerability
Published Dec 10, 2016
·Updated
Memory leak in the ehciprocessitd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.
Affected Software
2 affected components
Qemu Qemu<=2.7.1
openSUSE Leap=42.2
Remediation
Event History
Dec 10, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7995?
CVE-2016-7995 has a severity rating that indicates it can lead to denial of service due to memory consumption.
2
How do I fix CVE-2016-7995?
To fix CVE-2016-7995, upgrade QEMU to a version higher than 2.7.1 or apply the relevant patches if available.
3
Which software is affected by CVE-2016-7995?
CVE-2016-7995 affects QEMU versions up to and including 2.7.1 and openSUSE Leap 42.2.
4
What type of vulnerability is CVE-2016-7995?
CVE-2016-7995 is a memory leak vulnerability that can be exploited by local guest OS administrators.
5
Can CVE-2016-7995 be exploited remotely?
CVE-2016-7995 cannot be exploited remotely as it requires access by local guest OS administrators.