CVE-2016-9103: Infoleak
Published Dec 9, 2016
·Updated
The v9fsxattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
Affected Software
2 affected components
Qemu Qemu<=2.7.1
Debian Debian Linux=8.0
Remediation
Event History
Dec 9, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9103?
CVE-2016-9103 is categorized as a medium-severity vulnerability.
2
How do I fix CVE-2016-9103?
To mitigate CVE-2016-9103, upgrade QEMU to a version later than 2.7.1.
3
What systems are affected by CVE-2016-9103?
CVE-2016-9103 affects QEMU versions up to and including 2.7.1 and Debian Linux 8.0.
4
What type of attack does CVE-2016-9103 enable?
CVE-2016-9103 allows local guest OS administrators to read sensitive heap memory of the host.
5
Is CVE-2016-9103 remote exploit possible?
No, CVE-2016-9103 is a local vulnerability that requires access to the guest operating system.