CVE-2016-5337
MEDIUMQEMU - Info Disclosure
Title source: llmDescription
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
References (9)
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
16.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
Status
draft
Affected Products (5)
qemu/qemu
< 2.6.2
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
Timeline
Published
Jun 14, 2016
Tracked Since
Feb 18, 2026