Alpine: multiple qemu packages: security update to 2.8.1-r1

critical Tenable Cloud Security Plugin ID 406783

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an
out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A
privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute
arbitrary code on host with privileges of the QEMU process. (CVE-2017-2620)

- Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick
Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a
large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands. (CVE-2016-7994)

- Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows
local guest OS administrators to cause a denial of service (memory consumption) via a large number of
crafted buffer page select (PG) indexes. (CVE-2016-7995)

- The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS
administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure
to limit the number of link Transfer Request Blocks (TRB) to process. (CVE-2016-8576)

- Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS
administrators to cause a denial of service (memory consumption) via vectors related to an I/O read
operation. (CVE-2016-8577)

See Also

https://security.alpinelinux.org/vuln/CVE-2016-7994

https://security.alpinelinux.org/vuln/CVE-2016-7995

https://security.alpinelinux.org/vuln/CVE-2016-8576

https://security.alpinelinux.org/vuln/CVE-2016-8577

https://security.alpinelinux.org/vuln/CVE-2016-8578

https://security.alpinelinux.org/vuln/CVE-2016-8668

https://security.alpinelinux.org/vuln/CVE-2016-8909

https://security.alpinelinux.org/vuln/CVE-2016-8910

https://security.alpinelinux.org/vuln/CVE-2016-9101

https://security.alpinelinux.org/vuln/CVE-2016-9102

https://security.alpinelinux.org/vuln/CVE-2016-9103

https://security.alpinelinux.org/vuln/CVE-2016-9104

https://security.alpinelinux.org/vuln/CVE-2016-9105

https://security.alpinelinux.org/vuln/CVE-2016-9106

https://security.alpinelinux.org/vuln/CVE-2017-2615

https://security.alpinelinux.org/vuln/CVE-2017-2620

https://security.alpinelinux.org/vuln/CVE-2017-5525

https://security.alpinelinux.org/vuln/CVE-2017-5552

https://security.alpinelinux.org/vuln/CVE-2017-5578

https://security.alpinelinux.org/vuln/CVE-2017-5579

https://security.alpinelinux.org/vuln/CVE-2017-5667

https://security.alpinelinux.org/vuln/CVE-2017-5856

https://security.alpinelinux.org/vuln/CVE-2017-5857

https://security.alpinelinux.org/vuln/CVE-2017-5898

https://security.alpinelinux.org/vuln/CVE-2017-5931

Plugin Details

Severity: Critical

ID: 406783

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2017-2620

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/7/2016

Reference Information

CVE: CVE-2016-7994, CVE-2016-7995, CVE-2016-8576, CVE-2016-8577, CVE-2016-8578, CVE-2016-8668, CVE-2016-8909, CVE-2016-8910, CVE-2016-9101, CVE-2016-9102, CVE-2016-9103, CVE-2016-9104, CVE-2016-9105, CVE-2016-9106, CVE-2017-2615, CVE-2017-2620, CVE-2017-5525, CVE-2017-5552, CVE-2017-5578, CVE-2017-5579, CVE-2017-5667, CVE-2017-5856, CVE-2017-5857, CVE-2017-5898, CVE-2017-5931

BID: 93453, 93454, 93469, 93473, 93474, 93566, 93842, 93844, 93957, 93962, 93955, 93956, 93965, 93964, 95990, 96378, 95671, 95773, 95781, 95780, 95885, 95999, 95993, 96112, 96141