PatchSiren cyber security CVE debrief
CVE-2016-10028 Qemu CVE debrief
CVE-2016-10028 affects QEMU builds with Virtio GPU Device emulator support. A local guest OS user can send a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum capabilities size of 0, which can trigger an out-of-bounds read in virgl_cmd_get_capset and crash the process. The published impact is denial of service rather than data corruption or code execution. For operators, the main concern is availability of the QEMU host process that provides the affected virtual GPU functionality. Systems that do not use virtio-gpu 3D/virgl features, or that only run trusted guests, have lower practical exposure. NVD lists affected QEMU versions through 2.8.1.1.
- Vendor
- Qemu
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-27
- Advisory updated
- 2026-05-13
Who should care
QEMU maintainers, virtualization and cloud platform operators, desktop virtualization admins, and distro/security teams that ship QEMU with virtio-gpu 3D or virgl support enabled.
Technical summary
NVD describes an out-of-bounds read in virgl_cmd_get_capset in hw/display/virtio-gpu-3d.c. The issue is reachable from a guest through VIRTIO_GPU_CMD_GET_CAPSET when the maximum capabilities size is set to 0. The CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, matching a local guest-triggered availability impact. NVD maps the weakness to CWE-125 and lists vulnerable QEMU versions up to and including 2.8.1.1.
Defensive priority
Medium priority. Patch promptly on any host that exposes virtio-gpu 3D/virgl to untrusted or semi-trusted guests, because a guest can crash the QEMU process and disrupt service.
Recommended defensive actions
- Update QEMU to a vendor-fixed release or downstream package that includes the upstream fix referenced in the QEMU commit and mailing list advisories.
- If virtio-gpu 3D/virgl is not required, disable that device/emulation path to reduce exposure.
- Treat untrusted guest workloads as higher risk on hosts that provide virtual GPU acceleration.
- Verify deployed QEMU packages against the affected range noted by NVD (through version 2.8.1.1).
- Track vendor advisories and distro errata for backported fixes, since remediation may arrive outside the upstream version line.
Evidence notes
The supplied corpus shows the CVE was published by NVD on 2017-02-27 and later modified on 2026-05-13. NVD’s reference set includes an upstream QEMU commit, OSS-security patch postings dated 2016-12-20 and 2016-12-22, the QEMU-devel patch thread, and third-party advisories. NVD’s CPE criteria indicate affected QEMU versions through 2.8.1.1. This debrief avoids unsupported claims and is limited to the provided official and vendor-linked sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10028 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10028
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10028 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10028
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.gnu.org/archive/html/qemu-devel/2016-12/msg01903.html
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201701-49
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.