CVE-2016-2197: Qemu

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could use this flaw to crash the QEMU process instance resulting in DoS.

Affected products

  • Qemu Qemu: up to and including 2.5.1.1

Published 2016-12-29. Last modified 2026-06-17.