CVE-2016-1981

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instance resulting in DoS.

References

http://rhn.redhat.com/errata/RHSA-2016-2585.html

http://www.debian.org/security/2016/dsa-3469

http://www.debian.org/security/2016/dsa-3470

http://www.debian.org/security/2016/dsa-3471

http://www.openwall.com/lists/oss-security/2016/01/19/10

http://www.openwall.com/lists/oss-security/2016/01/22/1

http://www.securityfocus.com/bid/81549

https://bugzilla.redhat.com/show_bug.cgi?id=1298570

https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg03454.html

https://security.gentoo.org/glsa/201604-01

Details

Source: MITRE

Published: 2016-12-29

Updated: 2020-11-10

Type: CWE-835

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* versions up to 2.5.1.1 (inclusive)

Configuration 2

OR

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Tenable Plugins

View all (27 total)

IDNameProductFamilySeverity
99828EulerOS 2.0 SP1 : qemu-kvm (EulerOS-SA-2016-1066)NessusHuawei Local Security Checks
medium
95858Scientific Linux Security Update : qemu-kvm on SL7.x x86_64 (20161103)NessusScientific Linux Local Security Checks
medium
95331CentOS 7 : qemu-kvm (CESA-2016:2585)NessusCentOS Local Security Checks
medium
94706Oracle Linux 7 : qemu-kvm (ELSA-2016-2585)NessusOracle Linux Local Security Checks
medium
94548RHEL 7 : qemu-kvm (RHSA-2016:2585)NessusRed Hat Local Security Checks
medium
94000openSUSE Security Update : xen (openSUSE-2016-1170) (Bunker Buster)NessusSuSE Local Security Checks
critical
93180SUSE SLES11 Security Update : kvm (SUSE-SU-2016:1785-1)NessusSuSE Local Security Checks
critical
93177SUSE SLES11 Security Update : xen (SUSE-SU-2016:1745-1)NessusSuSE Local Security Checks
critical
93170SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2016:1703-1)NessusSuSE Local Security Checks
critical
93169SUSE SLES11 Security Update : kvm (SUSE-SU-2016:1698-1)NessusSuSE Local Security Checks
critical
91980openSUSE Security Update : qemu (openSUSE-2016-839)NessusSuSE Local Security Checks
critical
91660SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2016:1560-1)NessusSuSE Local Security Checks
critical
91249SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:1318-1)NessusSuSE Local Security Checks
critical
90759SUSE SLES11 Security Update : xen (SUSE-SU-2016:1154-1)NessusSuSE Local Security Checks
critical
90478openSUSE Security Update : xen (openSUSE-2016-439)NessusSuSE Local Security Checks
critical
90396SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2016:0955-1)NessusSuSE Local Security Checks
critical
90339GLSA-201604-01 : QEMU: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
90260openSUSE Security Update : xen (openSUSE-2016-413)NessusSuSE Local Security Checks
critical
90186SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:0873-1)NessusSuSE Local Security Checks
critical
90045Fedora 23 : xen-4.5.2-9.fc23 (2016-f4504e9445)NessusFedora Local Security Checks
high
90036Fedora 22 : xen-4.5.2-9.fc22 (2016-38b20aa50f)NessusFedora Local Security Checks
high
89605Fedora 22 : qemu-2.3.1-12.fc22 (2016-be042f7e6f)NessusFedora Local Security Checks
high
89599Fedora 23 : qemu-2.4.1-7.fc23 (2016-b49aaf2c56)NessusFedora Local Security Checks
high
88630Debian DSA-3471-1 : qemu - security updateNessusDebian Local Security Checks
critical
88629Debian DSA-3470-1 : qemu-kvm - security updateNessusDebian Local Security Checks
critical
88628Debian DSA-3469-1 : qemu - security updateNessusDebian Local Security Checks
critical
88576Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : qemu, qemu-kvm vulnerabilities (USN-2891-1)NessusUbuntu Local Security Checks
high