Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
2016-04-12T01:59:20.737
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | < 2.4.0 | Yes |
Application | qemu | qemu | 2.4.0 | Yes |
Application | qemu | qemu | 2.4.0 | Yes |
Application | qemu | qemu | 2.4.0 | Yes |