The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-06-14T14:00:00

Updated: 2024-08-06T01:00:59.975Z

Reserved: 2016-06-08T00:00:00

Link: CVE-2016-5338

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-06-14T14:59:02.760

Modified: 2023-02-12T23:23:16.027

Link: CVE-2016-5338

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-05-30T00:00:00Z

Links: CVE-2016-5338 - Bugzilla