CVE-2016-9914: Medium severity qemu vulnerability
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9914?
CVE-2016-9914 has a moderate severity level due to the potential for denial of service through memory leaks.
How do I fix CVE-2016-9914?
To fix CVE-2016-9914, update QEMU to a version later than 2.8.0-rc1 which includes the necessary cleanup operations.
Who is affected by CVE-2016-9914?
CVE-2016-9914 affects local privileged users of guest operating systems running QEMU versions up to 2.7.1 and specific release candidates.
What type of attack does CVE-2016-9914 enable?
CVE-2016-9914 enables a denial of service attack due to excessive host memory consumption and potential crashes of the QEMU process.
Where can I find more information about CVE-2016-9914?
More information about CVE-2016-9914 can typically be found in the release notes of QEMU or security mailing lists.