CVE-2016-1714

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.

References

http://rhn.redhat.com/errata/RHSA-2016-0081.html

http://rhn.redhat.com/errata/RHSA-2016-0082.html

http://rhn.redhat.com/errata/RHSA-2016-0083.html

http://rhn.redhat.com/errata/RHSA-2016-0084.html

http://rhn.redhat.com/errata/RHSA-2016-0085.html

http://rhn.redhat.com/errata/RHSA-2016-0086.html

http://rhn.redhat.com/errata/RHSA-2016-0087.html

http://rhn.redhat.com/errata/RHSA-2016-0088.html

http://www.debian.org/security/2016/dsa-3469

http://www.debian.org/security/2016/dsa-3470

http://www.debian.org/security/2016/dsa-3471

http://www.openwall.com/lists/oss-security/2016/01/11/7

http://www.openwall.com/lists/oss-security/2016/01/12/10

http://www.openwall.com/lists/oss-security/2016/01/12/11

http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html

http://www.securityfocus.com/bid/80250

http://www.securitytracker.com/id/1034858

https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg00428.html

https://security.gentoo.org/glsa/201604-01

Details

Source: MITRE

Published: 2016-04-07

Updated: 2019-12-27

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.4

Severity: HIGH

Tenable Plugins

View all (32 total)

IDNameProductFamilySeverity
117310RHEL 7 : qemu-kvm-rhev (RHSA-2016:0084)NessusRed Hat Local Security Checks
high
94000openSUSE Security Update : xen (openSUSE-2016-1170) (Bunker Buster)NessusSuSE Local Security Checks
critical
93180SUSE SLES11 Security Update : kvm (SUSE-SU-2016:1785-1)NessusSuSE Local Security Checks
critical
93177SUSE SLES11 Security Update : xen (SUSE-SU-2016:1745-1)NessusSuSE Local Security Checks
critical
93170SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2016:1703-1)NessusSuSE Local Security Checks
critical
93169SUSE SLES11 Security Update : kvm (SUSE-SU-2016:1698-1)NessusSuSE Local Security Checks
critical
91980openSUSE Security Update : qemu (openSUSE-2016-839)NessusSuSE Local Security Checks
critical
91660SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2016:1560-1)NessusSuSE Local Security Checks
critical
91369F5 Networks BIG-IP : QEMU vulnerability (K75248350)NessusF5 Networks Local Security Checks
high
91316OracleVM 3.4 : qemu-kvm (OVMSA-2016-0051)NessusOracleVM Local Security Checks
critical
91249SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:1318-1)NessusSuSE Local Security Checks
critical
90759SUSE SLES11 Security Update : xen (SUSE-SU-2016:1154-1)NessusSuSE Local Security Checks
critical
90478openSUSE Security Update : xen (openSUSE-2016-439)NessusSuSE Local Security Checks
critical
90396SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2016:0955-1)NessusSuSE Local Security Checks
critical
90339GLSA-201604-01 : QEMU: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
90260openSUSE Security Update : xen (openSUSE-2016-413)NessusSuSE Local Security Checks
critical
90186SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:0873-1)NessusSuSE Local Security Checks
critical
90045Fedora 23 : xen-4.5.2-9.fc23 (2016-f4504e9445)NessusFedora Local Security Checks
high
90036Fedora 22 : xen-4.5.2-9.fc22 (2016-38b20aa50f)NessusFedora Local Security Checks
high
88630Debian DSA-3471-1 : qemu - security updateNessusDebian Local Security Checks
critical
88629Debian DSA-3470-1 : qemu-kvm - security updateNessusDebian Local Security Checks
critical
88628Debian DSA-3469-1 : qemu - security updateNessusDebian Local Security Checks
critical
88576Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : qemu, qemu-kvm vulnerabilities (USN-2891-1)NessusUbuntu Local Security Checks
high
88510CentOS 7 : qemu-kvm (CESA-2016:0083)NessusCentOS Local Security Checks
high
88509CentOS 6 : qemu-kvm (CESA-2016:0082)NessusCentOS Local Security Checks
high
88506RHEL 6 : qemu-kvm-rhev (RHSA-2016:0081)NessusRed Hat Local Security Checks
high
88484Scientific Linux Security Update : qemu-kvm on SL7.x x86_64 (20160128)NessusScientific Linux Local Security Checks
high
88483Scientific Linux Security Update : qemu-kvm on SL6.x i386/x86_64 (20160128)NessusScientific Linux Local Security Checks
high
88482RHEL 7 : qemu-kvm (RHSA-2016:0083)NessusRed Hat Local Security Checks
high
88481RHEL 6 : qemu-kvm (RHSA-2016:0082)NessusRed Hat Local Security Checks
high
88478Oracle Linux 7 : qemu-kvm (ELSA-2016-0083)NessusOracle Linux Local Security Checks
high
88477Oracle Linux 6 : qemu-kvm (ELSA-2016-0082)NessusOracle Linux Local Security Checks
high