CVE-2017-16845 is a critical out-of-bounds access vulnerability in QEMU's hw/input/ps2.c, affecting various QEMU and Linux distributions from Canonical and Debian. This flaw arises from insufficient validation of 'rptr' and 'count' values during guest migration. With a CVSS score of 10.0, it presents a critical risk due to its network-based attack vector, low complexity, and potential for high impact on confidentiality and availability. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.11.2CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.