CVE-2015-2756: Medium severity debian linux vulnerability
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2756?
CVE-2015-2756 has a moderate severity as it can lead to denial of service and potential host crashes.
How do I fix CVE-2015-2756?
To fix CVE-2015-2756, update to the latest version of QEMU or apply the security patch provided by your Linux distribution.
What software is affected by CVE-2015-2756?
CVE-2015-2756 affects QEMU versions used in Debian, Fedora, and Ubuntu among others.
Can CVE-2015-2756 be exploited remotely?
CVE-2015-2756 cannot be exploited remotely as it requires local access to the HVM guest.
What should I do if I cannot apply the patch for CVE-2015-2756?
If you cannot apply the patch for CVE-2015-2756, consider restricting guest user access or disabling the use of PCI Express devices.