The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.
References
Configurations
History
No history.
Information
Published : 2016-12-10 00:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-7170
Mitre link : CVE-2016-7170
CVE.ORG link : CVE-2016-7170
JSON object : View
Products Affected
qemu
- qemu
debian
- debian_linux
opensuse
- leap
CWE
CWE-129
Improper Validation of Array Index