CVE-2015-6815: Low severity qemu vulnerability
Qemu emulator built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing transmit descriptor data when sending a network packet.
A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS.
Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg01199.html
Other sources
The processtxdesc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6815?
CVE-2015-6815 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2015-6815?
To fix CVE-2015-6815, upgrade to a patched version of QEMU that addresses the infinite loop issue.
Who is affected by CVE-2015-6815?
CVE-2015-6815 affects QEMU users running versions prior to 2.4.0.1 across several operating systems like Fedora, Ubuntu, and SUSE.
How does CVE-2015-6815 impact system security?
CVE-2015-6815 allows a privileged user inside a guest to crash the QEMU instance, leading to potential service disruptions.
What specific versions are vulnerable to CVE-2015-6815?
Vulnerable versions of QEMU to CVE-2015-6815 include all versions prior to 2.4.0.1.