Tracker / CVE-2016-3710
CVE-2016-3710
High 8.8
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| citrix | xenserver · … → 7.0 |
| debian | debian_linux |
| hp | helion_openstack |
| oracle | linux |
| oracle | vm_server |
| qemu | qemu |
| qemu | qemu · … → 2.5.1 |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_eus |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_workstation |
| redhat | openstack |
| redhat | virtualization |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.