Medium severity6.5NVD Advisory· Published Dec 29, 2016· Updated May 6, 2026
CVE-2016-9845
CVE-2016-9845
Description
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.nongnu.org/archive/html/qemu-devel/2016-11/msg00019.htmlnvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2016/12/05/15nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2016/12/05/22nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/94763nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201701-49nvdThird Party Advisory
News mentions
0No linked articles in our index yet.