hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. https://nvd.nist.gov/vuln/detail/CVE-2017-16845