CVE-2016-1568: Debian Linux
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Qemu Qemu: up to and including 2.5.1.1
- Red Hat Openstack: version 6.0 only; version 7.0 only; version 5.0 only
- Red Hat Virtualization: version 3.0 only
Published 2016-04-12. Last modified 2026-06-17.