CVE-2016-6351
MEDIUMQEMU - DoS/Arbitrary Code Execution
Title source: llmDescription
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
References (8)
Scores
CVSS v3
6.7
EPSS
0.0017
EPSS Percentile
37.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
Status
published
Affected Products (6)
qemu/qemu
< 2.6.2
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
n/a/n/a
Timeline
Published
Sep 07, 2016
Tracked Since
Feb 18, 2026