Qemu: nvram: OOB r/w access in processing firmware configurations
Published Apr 7, 2016
8.1
HIGHCVSS 3.0
EPSS 6.08%
Description
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.
Affected products
No data.
No data.
RHEV 3.6 For IBM Power Systems
qemu-kvm-rhev-10:2.3.0-31.el7_2.7
Fixed · RHSA-2016:0084
RHEV 3.X Hypervisor and Agents for RHEL-6
qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.4
Fixed · RHSA-2016:0081
RHEV 3.X Hypervisor and Agents for RHEL-7
qemu-kvm-rhev-10:2.3.0-31.el7_2.7
Fixed · RHSA-2016:0084
Red Hat Enterprise Linux 6
qemu-kvm-2:0.12.1.2-2.479.el6_7.4
Fixed · RHSA-2016:0082
Red Hat Enterprise Linux 7
qemu-kvm-10:1.5.3-105.el7_2.3
Fixed · RHSA-2016:0083
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.4
Fixed · RHSA-2016:0085
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7
qemu-kvm-rhev-10:2.3.0-31.el7_2.7
Fixed · RHSA-2016:0086
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7
qemu-kvm-rhev-10:2.3.0-31.el7_2.7
Fixed · RHSA-2016:0087
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7
qemu-kvm-rhev-10:2.3.0-31.el7_2.7
Fixed · RHSA-2016:0088
Red Hat Enterprise Linux 5
kvm
Will not fix
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 6
qemu-kvm-rhev
Affected
Red Hat OpenStack Platform 8 (Liberty)
qemu-kvm-rhev
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV 3.6 For IBM Power Systems | qemu-kvm-rhev-10:2.3.0-31.el7_2.7 | Fixed | RHSA-2016:0084 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.4 | Fixed | RHSA-2016:0081 |
| RHEV 3.X Hypervisor and Agents for RHEL-7 | qemu-kvm-rhev-10:2.3.0-31.el7_2.7 | Fixed | RHSA-2016:0084 |
| Red Hat Enterprise Linux 6 | qemu-kvm-2:0.12.1.2-2.479.el6_7.4 | Fixed | RHSA-2016:0082 |
| Red Hat Enterprise Linux 7 | qemu-kvm-10:1.5.3-105.el7_2.3 | Fixed | RHSA-2016:0083 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.4 | Fixed | RHSA-2016:0085 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | qemu-kvm-rhev-10:2.3.0-31.el7_2.7 | Fixed | RHSA-2016:0086 |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | qemu-kvm-rhev-10:2.3.0-31.el7_2.7 | Fixed | RHSA-2016:0087 |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | qemu-kvm-rhev-10:2.3.0-31.el7_2.7 | Fixed | RHSA-2016:0088 |
| Red Hat Enterprise Linux 5 | kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm-rhev | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | qemu-kvm-rhev | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.08% (0.06085) | 93.19th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.13% (0.06135) | 92.51th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.34% (0.00343) | 54.72th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.86% (0.00860) | 82.99th | v3 (v2023.03.01) |
| Jul 8, 2024 | 0.86% (0.00860) | 82.40th | v3 (v2023.03.01) |
| Jun 5, 2024 | 0.61% (0.00607) | 78.00th | v3 (v2023.03.01) |
| Feb 28, 2024 | 0.43% (0.00426) | 73.75th | v3 (v2023.03.01) |
| Jan 29, 2024 | 0.43% (0.00426) | 71.75th | v3 (v2023.03.01) |
| Nov 24, 2023 | 0.37% (0.00374) | 69.71th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00271) | 62.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.34% (0.02336) | 81.42th | v2 (v2022.01.01) |
| Feb 13, 2023 | 2.34% (0.02336) | 80.92th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.44% (0.02444) | 81.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.34% (0.02336) | 79.65th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.34% (0.02336) | 58.29th | v2 (v2022.01.01) |
References (23)
- http://rhn.redhat.com/errata/RHSA-2016-0081.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0082.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0083.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0084.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0085.html vendor-advisoryx_refsource_REDHATIssue TrackingThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0086.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0087.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0088.html vendor-advisoryx_refsource_REDHATIssue TrackingThird Party AdvisoryVDB Entry
- http://www.debian.org/security/2016/dsa-3469 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2016/dsa-3470 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2016/dsa-3471 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2016/01/11/7 mailing-listx_refsource_MLISTThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/10 mailing-listx_refsource_MLISTThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/11 mailing-listx_refsource_MLISTThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/80250 vdb-entryx_refsource_BIDThird Party Advisory
- http://www.securitytracker.com/id/1034858 vdb-entryx_refsource_SECTRACKThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-1714 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1296060 Issue Tracking
- https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg00428.html mailing-listx_refsource_MLISTVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1714
- https://security.gentoo.org/glsa/201604-01 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2016-1714
Change history (0)
No recorded changes yet.