Medium severity6.0NVD Advisory· Published Nov 4, 2016· Updated May 6, 2026
CVE-2016-8668
CVE-2016-8668
Description
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.openwall.com/lists/oss-security/2016/10/14/8nvdMailing ListPatchThird Party Advisory
- lists.gnu.org/archive/html/qemu-devel/2016-10/msg02501.htmlnvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-updates/2016-12/msg00140.htmlnvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2016/10/15/9nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/93566nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201611-11nvdThird Party Advisory
News mentions
0No linked articles in our index yet.