QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.5.1.1 (including) |
Qemu | Qemu | 2.6.0-rc0 (including) | 2.6.0-rc0 (including) |
Qemu | Qemu | 2.6.0-rc1 (including) | 2.6.0-rc1 (including) |
Qemu | Qemu | 2.6.0-rc2 (including) | 2.6.0-rc2 (including) |
Qemu | Qemu | 2.6.0-rc3 (including) | 2.6.0-rc3 (including) |
Qemu | Qemu | 2.6.0-rc4 (including) | 2.6.0-rc4 (including) |
Qemu | Ubuntu | devel | * |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | upstream | * |
Qemu | Ubuntu | vivid | * |
Qemu | Ubuntu | wily | * |