CVE-2015-8567: High severity qemu vulnerability
Last updated 24 July 2024
Other sources
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
— Launchpad
Qemu emulator built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to a memory leakage flaw. It occurs when a guest repeatedly tries to activate the vmxnet3 device.
A privileged guest user could use this flaw to leak host memory, resulting in DoS on the host.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2015-12/msg02299.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2015/12/15/10
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8567?
CVE-2015-8567 is a vulnerability in QEMU that allows remote attackers to cause a denial of service by consuming excessive memory.
How severe is CVE-2015-8567?
CVE-2015-8567 has a severity rating of 7.7, which is considered high.
Which software versions are affected by CVE-2015-8567?
CVE-2015-8567 affects QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and 2.5.1.1, as well as various versions of Ubuntu, Debian, SUSE, openSUSE, Fedora, and Canonical Ubuntu Linux.
How can I fix CVE-2015-8567?
To fix CVE-2015-8567, you should apply the appropriate security patches provided by the software vendor.
Where can I find more information about CVE-2015-8567?
You can find more information about CVE-2015-8567 at the following references: http://www.securityfocus.com/bid/79721, http://www.debian.org/security/2016/dsa-3471, http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176558.html