← Vulnerability feed

Vulnerability record · CVE-2016-1714 · published 7 April 2016

CVE-2016-1714: Redhat openstack memory buffer overflow vulnerability

Redhat · Openstack

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.

8.1 CVSS 3.0 High EPSS 6.1% · top 6.8% CWE-119 · Memory buffer overflow
8.1CVSS 3.0 base score, v2 6.9
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
38References
17 Jun 2026Last modified by NVD

Description

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2016-0081.html
http://rhn.redhat.com/errata/RHSA-2016-0082.html
http://rhn.redhat.com/errata/RHSA-2016-0083.html
http://rhn.redhat.com/errata/RHSA-2016-0084.html
http://rhn.redhat.com/errata/RHSA-2016-0085.html Issue TrackingThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-0086.html
http://rhn.redhat.com/errata/RHSA-2016-0087.html
http://rhn.redhat.com/errata/RHSA-2016-0088.html Issue TrackingThird Party AdvisoryVDB Entry
http://www.debian.org/security/2016/dsa-3469
http://www.debian.org/security/2016/dsa-3470
http://www.debian.org/security/2016/dsa-3471
http://www.openwall.com/lists/oss-security/2016/01/11/7 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/01/12/10 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/01/12/11 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html Third Party Advisory
http://www.securityfocus.com/bid/80250 Third Party Advisory
http://www.securitytracker.com/id/1034858 Third Party Advisory
https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg00428.html Vendor Advisory
https://security.gentoo.org/glsa/201604-01
http://rhn.redhat.com/errata/RHSA-2016-0081.html
http://rhn.redhat.com/errata/RHSA-2016-0082.html
http://rhn.redhat.com/errata/RHSA-2016-0083.html
http://rhn.redhat.com/errata/RHSA-2016-0084.html
http://rhn.redhat.com/errata/RHSA-2016-0085.html Issue TrackingThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-0086.html
http://rhn.redhat.com/errata/RHSA-2016-0087.html
http://rhn.redhat.com/errata/RHSA-2016-0088.html Issue TrackingThird Party AdvisoryVDB Entry
http://www.debian.org/security/2016/dsa-3469
http://www.debian.org/security/2016/dsa-3470
http://www.debian.org/security/2016/dsa-3471
http://www.openwall.com/lists/oss-security/2016/01/11/7 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/01/12/10 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/01/12/11 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html Third Party Advisory
http://www.securityfocus.com/bid/80250 Third Party Advisory
http://www.securitytracker.com/id/1034858 Third Party Advisory
https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg00428.html Vendor Advisory
https://security.gentoo.org/glsa/201604-01

Track CVE-2016-1714 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed7.8CVE-2015-5287ABRT abrt-hook-ccpp symlink privilege escalationThe abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a l…KEVEPSS 5.0%analysed7.8CVE-2014-3153Linux Kernel futex_requeue Local Privilege EscalationThe futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different fute…KEVEPSS 37%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed5.5CVE-2014-0196Linux kernel n_tty_write race condition allows local privilege escalationThe n_tty_write function in the Linux kernel through 3.14.3 mishandles tty driver access in the LECHO & !OPOST case, creating a race condition betwee…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1714), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.