CVE-2016-4020
MEDIUMQEMU - Info Disclosure
Title source: llmDescription
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
References (11)
Scores
CVSS v3
6.5
EPSS
0.0008
EPSS Percentile
24.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Classification
Status
draft
Affected Products (25)
qemu/qemu
< 2.6.2
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
... and 10 more
Timeline
Published
May 25, 2016
Tracked Since
Feb 18, 2026