CVE-2016-7161: Debian Linux

Critical severity, CVSS 9.8. EPSS: 6.1% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Qemu Qemu: up to and including 2.6.2; version 2.7.0 only

Published 2016-10-05. Last modified 2026-06-17.