DEBIAN-CVE-2016-4454

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 01 Jun 2016, 22:59
Last modified:28 Apr 2026, 20:15

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
6 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jun 2016, 22:59
Published
Vulnerability first disclosed
28 Apr 2026, 20:15
Last Modified
Vulnerability information updated

Description

The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.

CVSS Metrics

  • v3.1MEDIUMScore: 6CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

Affected Systems

  • debianqemu

    < 1:2.6+dfsg-3 | < 1:2.6+dfsg-3 | < 1:2.6+dfsg-3 | < 1:2.6+dfsg-3

References (1)