CVE-2016-2841
MEDIUMQemu < 2.5.0 - Improper Input Validation
Title source: ruleDescription
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.
References (9)
Scores
CVSS v3
6.0
EPSS
0.0006
EPSS Percentile
18.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Classification
CWE
CWE-20
Status
draft
Affected Products (5)
qemu/qemu
< 2.5.0
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
Timeline
Published
Jun 16, 2016
Tracked Since
Feb 18, 2026