Back

HIGH

Qemu: ide: ahci use-after-free vulnerability in aio port commands

Published Apr 8, 2016

Description

Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.

Affected products

Remediation

Red Hat statement

The vector of exploit requires to enable TIOCSTI with sysctl, because it is by default disabled since RHEL9 and on. Then, the user would have to be in root terminal, from there the user would have to run a malicious app that would use TIOCSTI to jump out of the child non-root shell back to the parent root shell.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 8, 2016
Updated Aug 5, 2024
Reserved Jan 9, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 8, 2016