ZeroHour

CVE-2016-8576

CVSS 3.1
6.0 medium
EPSS
<1%p32
Published
()
Modified
Description

The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.

Vendors
qemuopensuseredhatdebian
Products
qemu, leap, openstack, virtualization, debian linux
Weakness
CWE-770
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.