Heap-based buffer overflow in the iscsiaioioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5126.json"