CVE-2016-4439 describes an out-of-bounds write vulnerability in the QEMU 53C9X Fast SCSI Controller (FSC) support, specifically within the esp_reg_write function in hw/scsi/esp.c. This flaw, caused by improper command buffer length checking, affects various QEMU installations across Canonical and Debian Linux distributions. With a CVSS score of 6.7 (Medium), this vulnerability allows local guest OS administrators to trigger a denial of service (QEMU process crash) or potentially execute arbitrary code on the QEMU host. The attack requires high privileges (PR:H) but has low attack complexity (AC:L) and no user interaction (UI:N). There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public awareness or active threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
<= 2.6.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.