Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
https://security.gentoo.org/glsa/201510-02
https://lists.nongnu.org/archive/html/qemu-devel/2015-07/msg04558.html