CVE-2016-2198: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
Affected products
Published 2016-12-29. Last modified 2026-06-17.