First published: Thu Dec 29 2016(Updated: )
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <2.8.0 | |
QEMU KVM | =2.8.0-rc0 | |
QEMU KVM | =2.8.0-rc1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9916 has a moderate severity rating due to its potential to cause denial of service through a memory leak.
To fix CVE-2016-9916, upgrade to a version of QEMU that is higher than 2.8.0, which addresses the memory leak issue.
CVE-2016-9916 affects local privileged guest OS users running QEMU versions up to 2.8.0.
Vulnerable systems include QEMU versions below 2.8.0 and Debian Linux version 8.0.
The consequences of CVE-2016-9916 include host memory consumption which may lead to a crash of the QEMU process.