CVE-2016-5126

Impact:
Moderate
Public Date:
2016-05-24
CWE:
CWE-120
Bugzilla:
1340924: CVE-2016-5126 Qemu: block: iscsi: buffer overflow in iscsi_aio_ioctl
Quick Emulator(QEMU) built with the Block driver for iSCSI images support (virtio-blk) is vulnerable to a heap-based buffer overflow issue. The flaw could occur while processing iSCSI asynchronous I/O ioctl(2) calls. A user inside a guest could exploit this flaw to crash the QEMU process resulting in denial of service, or potentially leverage it to execute arbitrary code with QEMU-process privileges on the host.

Find out more about CVE-2016-5126 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:A/AC:M/Au:N/C:N/I:P/A:P
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Partial

CVSS v3 metrics

CVSS3 Base Score 5.4
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact Low
Availability Impact Low

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (qemu-kvm) RHSA-2016:1606 2016-08-11
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1653 2016-08-23
Red Hat OpenStack Platform 9.0 (qemu-kvm-rhev) RHSA-2016:1763 2016-08-24
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (qemu-kvm-rhev) RHSA-2016:1607 2016-08-12
Red Hat OpenStack Platform 8.0 (Liberty) (qemu-kvm-rhev) RHSA-2016:1756 2016-08-24
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1655 2016-08-23
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1654 2016-08-23

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 10 qemu-kvm-rhev Not affected
Red Hat Enterprise Linux 6 qemu-kvm Not affected
Red Hat Enterprise Linux 5 xen Not affected
Red Hat Enterprise Linux 5 kvm Not affected

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.