First published: Fri Dec 23 2016(Updated: )
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9908 is classified as a moderate severity vulnerability due to its potential for information leakage.
To fix CVE-2016-9908, update QEMU to version 2.8.1.2 or later which contains the necessary patches.
CVE-2016-9908 is an information leakage vulnerability affecting the Virtio GPU Device emulator in QEMU.
CVE-2016-9908 affects QEMU installations that utilize the Virtio GPU Device emulator up to version 2.8.1.1.
Yes, guest users or processes can potentially exploit CVE-2016-9908 to leak sensitive information from the host memory.