CVE-2016-5105
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- qemu/qemu · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2016/05/25/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/26/7Mailing List, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3047-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3047-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1339583Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg04419.htmlMailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/25/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/26/7Mailing List, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3047-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3047-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1339583Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg04419.htmlMailing List, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.