CVE-2016-9102: Medium severity qemu vulnerability
Memory leak in the v9fsxattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9102?
CVE-2016-9102 is considered a moderate severity vulnerability due to the potential for denial of service.
How do I fix CVE-2016-9102?
To fix CVE-2016-9102, upgrade to a version of QEMU later than 2.7.1 where this vulnerability has been addressed.
Who is affected by CVE-2016-9102?
CVE-2016-9102 affects local guest OS administrators using vulnerable versions of QEMU and Debian 8.0.
What does CVE-2016-9102 exploit?
CVE-2016-9102 exploits a memory leak in the v9fs_xattrcreate function, leading to high memory consumption.
What can be the impact of CVE-2016-9102?
The impact of CVE-2016-9102 can result in a denial of service, causing the QEMU process to crash.