QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.9.1 (including) |
Qemu | Qemu | 2.10.0-rc0 (including) | 2.10.0-rc0 (including) |
Qemu | Qemu | 2.10.0-rc1 (including) | 2.10.0-rc1 (including) |
Qemu | Qemu | 2.10.0-rc2 (including) | 2.10.0-rc2 (including) |
Qemu | Ubuntu | xenial | * |
Qemu | Ubuntu | zesty | * |