CVE-2016-8576

MEDIUM

QEMU - DoS

Title source: llm

Description

The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.

Scores

CVSS v3 6.0
EPSS 0.0011
EPSS Percentile 29.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Classification

CWE
CWE-770
Status published

Affected Products (11)

qemu/qemu < 2.7.1
opensuse/leap
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/virtualization
debian/debian_linux
n/a/n/a

Timeline

Published Nov 04, 2016
Tracked Since Feb 18, 2026