CVE Vulnerabilities

CVE-2016-8910

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Nov 04, 2016 | Modified: Apr 12, 2025
CVSS 3.x
6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
3 LOW
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu*2.7.1 (including)
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat OpenStack Platform 10.0 (Newton)RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat OpenStack Platform 11.0 (Ocata)RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat OpenStack Platform 8.0 (Liberty)RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat OpenStack Platform 9.0 (Mitaka)RedHatqemu-kvm-rhev-10:2.9.0-10.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatqemu-kvm-rhev-10:2.9.0-14.el7*
QemuUbuntudevel*
QemuUbuntuesm-infra-legacy/trusty*
QemuUbuntuesm-infra/xenial*
QemuUbuntutrusty*
QemuUbuntutrusty/esm*
QemuUbuntuxenial*
QemuUbuntuyakkety*
Qemu-kvmUbuntuprecise*

References