CVE
- Id
- 102676
- CVE No.
- CVE-2017-5856
- Status
- Candidate
- Description
- Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.
- Phase
- Assigned (20170201)
- Votes
- None (candidate not yet proposed)
- Comments