CVE-2016-9921
MEDIUMQemu < 2.7.1 - Divide By Zero
Title source: ruleDescription
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0010
EPSS Percentile
28.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Classification
CWE
CWE-369
Status
draft
Affected Products (12)
qemu/qemu
< 2.7.1
qemu/qemu
qemu/qemu
qemu/qemu
debian/debian_linux
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/virtualization
Timeline
Published
Dec 23, 2016
Tracked Since
Feb 18, 2026