CVE-2016-7161: Debian Linux
Critical severity, CVSS 9.8. EPSS: 6.1% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
Affected products
Published 2016-10-05. Last modified 2026-06-17.