CVE-2016-9846 describes a memory leakage vulnerability in QEMU's Virtio GPU Device emulator, specifically within the update_cursor_data_virgl function. A malicious guest user or process could exploit this flaw to leak host memory bytes, leading to a Denial of Service (DoS) for the host system. With a CVSS score of 6.5 (MEDIUM), the vulnerability requires local access and has low attack complexity, but its primary impact is availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.1CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
2.8.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.8.0:rc0:*:*:*:*:*:* | ||
2.8.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.8.0:rc1:*:*:*:*:*:* | ||
2.8.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.8.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.