CVE-2016-6888
MEDIUMQemu < 2.6.2 - Integer Overflow
Title source: ruleDescription
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
References (9)
Scores
CVSS v3
4.4
EPSS
0.0010
EPSS Percentile
26.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-190
Status
published
Affected Products (14)
qemu/qemu
< 2.6.2
qemu/qemu
qemu/qemu
qemu/qemu
qemu/qemu
debian/debian_linux
redhat/virtualization
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
n/a/n/a
Timeline
Published
Dec 10, 2016
Tracked Since
Feb 18, 2026