1.9
CVSSv2

CVE-2016-7466

Published: 10/12/2016 Updated: 12/02/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 6 | Impact Score: 4 | Exploitability Score: 1.5
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

opensuse leap 42.2

redhat openstack 7.0

redhat openstack 6.0

redhat openstack 10

redhat openstack 9

redhat openstack 8

redhat openstack 11

redhat virtualization 4.0

Vendor Advisories

Debian Bug report logs - #838687 qemu: CVE-2016-7466: memory leakage during device unplug Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Sep 2016 16:21:05 UTC Severity: important Tags: patch, ...
Several security issues were fixed in QEMU ...