An information-exposure flaw was found in Quick Emulator (QEMU) in Task Priority Register (TPR) optimizations for 32-bit Windows guests. The flaw could occur while accessing TPR. A privileged user inside a guest could use this issue to read portions of the host memory.
Find out more about CVE-2016-4020 from the MITRE CVE dictionary dictionary and NIST NVD.
This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle:
https://access.redhat.com/support/policy/updates/errata/.
Base Score | 2.9 |
---|---|
Base Metrics | AV:A/AC:M/Au:N/C:P/I:N/A:N |
Access Vector | Adjacent Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
CVSS3 Base Score | 3.4 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N |
Attack Vector | Adjacent Network |
Attack Complexity | High |
Privileges Required | None |
User Interaction | None |
Scope | Changed |
Confidentiality | Low |
Integrity Impact | None |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat OpenStack Platform 8.0 (Liberty) (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat OpenStack Platform 11.0 (Ocata) (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (qemu-kvm-rhev) | RHSA-2017:2392 | 2017-08-01 |
Red Hat OpenStack Platform 9.0 (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat OpenStack Platform 10 (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 (qemu-kvm-rhev) | RHSA-2017:2408 | 2017-08-01 |
Red Hat Enterprise Linux 7 (qemu-kvm) | RHSA-2017:1856 | 2017-08-01 |
Platform | Package | State |
---|---|---|
Red Hat OpenStack Platform 12.0 | qemu-kvm-rhev | Not affected |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) | qemu-kvm-rhev | Will not fix |
Red Hat Enterprise Linux 6 | qemu-kvm | Not affected |
Red Hat Enterprise Linux 5 | xen | Not affected |
Red Hat Enterprise Linux 5 | kvm | Not affected |