CVE-2016-6351

medium
Published 2016-09-07 · Modified 2026-05-06
CVSS v3
6.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.2
VIR risk
6.7

Description

The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.

Predictions

Exploit likelihood
66%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6351

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-6351.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian8.0affected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu16.04affected
debian debianbookwormfixed1:2.6+dfsg-3.1
debian debianbullseyefixed1:2.6+dfsg-3.1
debian debianforkyfixed1:2.6+dfsg-3.1
debian debiansidfixed1:2.6+dfsg-3.1
debian debiantrixiefixed1:2.6+dfsg-3.1

Application impact

VendorProductVersionsFixed
qemuqemu{"endIncluding":"2.6.2"}

References

Verify integrity in audit chain (admin only). AS-IS.