CVE-2016-2392
16.06.2016, 18:59
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.Enginsight
Vendor | Product | Version |
---|---|---|
qemu | qemu | 2.5.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.10 |
canonical | ubuntu_linux | 16.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References