← Back

CVE-2011-3346

nvd nist
Published: Apr 1, 2014Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:L/AC:H/Au:N/C:N/I:N/A:C
Exploitability: 1.9 / Impact: 6.9
Source: NVD

Description

Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.

Affected (5)

Products: Qemu: Qemu · Redhat: Enterprise Linux · Xen: Xen
1 product
Qemu
1 product
Enterprise Linux
1 product
Xen
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Qemu
Up to 0.15.1
Version 0.15.0 rc1
Version 0.15.0 rc2
Version 5
All versions

Timeline

No history available yet.