CVE-2016-9923: Qemu
Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in DoS.
Affected products
- Qemu Qemu: up to and including 2.7.1
Published 2016-12-23. Last modified 2026-06-17.