Resource exhaustion in QEMU - CVE-2016-9907
Published: December 24, 2016 / Updated: August 9, 2020
QEMU
Detailed vulnerability description
The vulnerability allows a local authenticated user to a crash the entire system.
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
How to mitigate CVE-2016-9907
Sources
- http://www.openwall.com/lists/oss-security/2016/12/08/3
- http://www.securityfocus.com/bid/94759
- https://access.redhat.com/errata/RHSA-2017:2392
- https://access.redhat.com/errata/RHSA-2017:2408
- https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html
- https://security.gentoo.org/glsa/201701-49