CVE-2016-9776

Published: 29 December 2016

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS.

Priority

Low

CVSS 3 base score: 5.5

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(1:2.8+dfsg-3ubuntu2)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(1:2.8+dfsg-3ubuntu2)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(1:2.8+dfsg-3ubuntu2)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1:2.5+dfsg-5ubuntu10.11)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.0.0+dfsg-2ubuntu1.33)
Patches:
Upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=77d54985b85a0cb760330ec2bd92505e0a2a97a9
qemu-kvm
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Patches:
Upstream: https://lists.gnu.org/archive/html/qemu-devel/2016-11/msg05324.html