CVE-2016-2841

MEDIUM

Qemu < 2.5.0 - Improper Input Validation

Title source: rule

Description

The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.

Scores

CVSS v3 6.0
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Classification

CWE
CWE-20
Status draft

Affected Products (5)

qemu/qemu < 2.5.0
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux

Timeline

Published Jun 16, 2016
Tracked Since Feb 18, 2026