CVE-2016-7421
MEDIUMQemu < 2.7.1 - Denial of Service
Title source: ruleDescription
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
References (7)
Scores
CVSS v3
4.4
EPSS
0.0011
EPSS Percentile
29.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-834
Status
published
Affected Products (3)
qemu/qemu
< 2.7.1
debian/debian_linux
n/a/n/a
Timeline
Published
Dec 10, 2016
Tracked Since
Feb 18, 2026