CVE-2016-6888
—CVSS 3.1
4.4 medium
EPSS
<1%p31
Published
()
Modified
Description
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
In the news0 stories
No ingested article mentions this CVE yet.