VulnerabilityModified
CVE-2016-4020
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
MEDIUM 6.5EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Affected
- qemu/qemu · canonical/ubuntu linux · debian/debian linux · redhat/openstack · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · redhat/virtualization
- Source
- secalert@redhat.com
References
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=691a02e2ce0c413236a78dee6f2651c937b09fb0
- http://www.securityfocus.com/bid/86067Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2974-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1856Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2392Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2408Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1313686Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01106.htmlPatch, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.htmlPatch, Third Party Advisory
- https://security.gentoo.org/glsa/201609-01Third Party Advisory
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=691a02e2ce0c413236a78dee6f2651c937b09fb0
- http://www.securityfocus.com/bid/86067Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2974-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1856Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2392Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2408Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1313686Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01106.htmlPatch, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.htmlPatch, Third Party Advisory
- https://security.gentoo.org/glsa/201609-01Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.