CVE-2016-2538: Qemu
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_dataout function.
Affected products
- Qemu Qemu: up to and including 2.5.0
Published 2016-06-16. Last modified 2026-06-17.