CVE-2016-3710

high
Published 2016-05-11 · Modified 2026-05-06
CVSS v3
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
7.2
VIR risk
8.8

Description

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-3710

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg01197.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164862

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-3710.html

OS impact

OSVersionStatusFixed in
suse slesaffected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.10affected
ubuntu ubuntu16.04affected
debian debian8.0affected
redhat rhel6.0affected
redhat rhel7.0affected
debian debianbookwormfixed1:2.6+dfsg-1
debian debianbullseyefixed1:2.6+dfsg-1
debian debianforkyfixed1:2.6+dfsg-1
debian debiansidfixed1:2.6+dfsg-1
debian debiantrixiefixed1:2.6+dfsg-1

Application impact

VendorProductVersionsFixed
hp hphelion_openstack2.0.0
hp hphelion_openstack2.1.0
hp hphelion_openstack2.1.2
hp hphelion_openstack2.1.4
qemuqemu{"endIncluding":"2.5.1"}
qemuqemu2.6.0
oracle oraclevm_server3.2
oracle oraclevm_server3.3
oracle oraclevm_server3.4
citrixxenserver{"endIncluding":"7.0"}
redhat redhatopenstack5.0
redhat redhatopenstack6.0
redhat redhatopenstack7.0
redhat redhatopenstack8
redhat redhatvirtualization3.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.