CVE-2016-5403

Impact:
Moderate
Public Date:
2016-07-27
Bugzilla:
1358359: CVE-2016-5403 Qemu: virtio: unbounded memory allocation on host via guest leading to DoS
Quick Emulator (QEMU) built with the virtio framework is vulnerable to an unbounded memory allocation issue. It was found that a malicious guest user could submit more requests than the virtqueue size permits. Processing a request allocates a VirtQueueElement results in unbounded memory allocation on the host controlled by the guest.

Find out more about CVE-2016-5403 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 2.3
Base Metrics AV:A/AC:M/Au:S/C:N/I:N/A:P
Access Vector Adjacent Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

CVSS v3 metrics

CVSS3 Base Score 3.4
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact None
Availability Impact Low

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Virtualization 5 (kvm) RHSA-2016:1943 2016-09-27
RHEV Agents (vdsm) (qemu-kvm-rhev) RHSA-2016:1586 2016-08-09
Red Hat Enterprise Linux 7 (qemu-kvm) RHSA-2016:1606 2016-08-11
Red Hat Enterprise Linux 6 (qemu-kvm) RHSA-2016:1585 2016-08-09
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1653 2016-08-23
Red Hat OpenStack Platform 9.0 (qemu-kvm-rhev) RHSA-2016:1763 2016-08-24
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (qemu-kvm-rhev) RHSA-2016:1607 2016-08-12
Red Hat OpenStack Platform 8.0 (Liberty) (qemu-kvm-rhev) RHSA-2016:1756 2016-08-24
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 (qemu-kvm-rhev) RHSA-2016:1652 2016-08-23
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1655 2016-08-23
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 (qemu-kvm-rhev) RHSA-2016:1654 2016-08-23

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 10 qemu-kvm-rhev Not affected
Red Hat Enterprise Linux 5 xen Fix deferred

Acknowledgements

Red Hat would like to thank hongzhenhao (Marvel Team) for reporting this issue.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.