First published: Thu Dec 29 2016(Updated: )
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle backend.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.7.1 | |
QEMU KVM | =2.8.0-rc0 | |
QEMU KVM | =2.8.0-rc1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9915 is classified as a denial of service vulnerability due to memory leak issues in QEMU.
To resolve CVE-2016-9915, upgrade QEMU to version 2.8.0 or later, or apply the relevant patches.
CVE-2016-9915 affects local privileged guest OS users utilizing QEMU versions up to 2.7.1 and specific release candidates.
CVE-2016-9915 impacts systems running QEMU, especially those used for virtualization and cloud environments.
The exploitation of CVE-2016-9915 can lead to excessive host memory consumption and may cause the QEMU process to crash.