Information disclosure in QEMU - CVE-2016-9908

 

Information disclosure in QEMU - CVE-2016-9908

Published: December 24, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU39963
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9908
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.


Affected software

QEMU

How to mitigate CVE-2016-9908

Install update from vendor's website.


External References

Related Security Bulletins