CVE-2015-8568: Medium severity qemu vulnerability
Last updated 24 July 2024
Other sources
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2015-8568.
What is the title of the vulnerability?
The title of the vulnerability is 'Memory leak in QEMU when built with a VMWARE VMXNET3 paravirtual NIC emulator support allows local g…'.
What is the severity of CVE-2015-8568?
The severity of CVE-2015-8568 is medium (6.5).
How does CVE-2015-8568 affect QEMU?
CVE-2015-8568 affects QEMU when built with a VMWARE VMXNET3 paravirtual NIC emulator support.
How can local guest users exploit CVE-2015-8568?
Local guest users can cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
Which software versions are affected by CVE-2015-8568?
QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and 2.5.1 are affected by CVE-2015-8568.
How can I fix CVE-2015-8568 in QEMU on Ubuntu Trusty?
To fix CVE-2015-8568 in QEMU on Ubuntu Trusty, update to version 2.0.0+dfsg-2ubuntu1.22 or later.
How can I fix CVE-2015-8568 in QEMU on Ubuntu Wily?
To fix CVE-2015-8568 in QEMU on Ubuntu Wily, update to version 1:2.3+dfsg-5ubuntu9.2 or later.
How can I fix CVE-2015-8568 in QEMU on Debian 8.0?
To fix CVE-2015-8568 in QEMU on Debian 8.0, update to the latest version available.
How can I fix CVE-2015-8568 in QEMU on Debian 10?
To fix CVE-2015-8568 in QEMU on Debian 10, update to version 1:3.1+dfsg-8+deb10u8 or later.
How can I fix CVE-2015-8568 in QEMU on Debian 11?
To fix CVE-2015-8568 in QEMU on Debian 11, update to version 1:5.2+dfsg-11+deb11u3 or later.
How can I fix CVE-2015-8568 in QEMU on Debian 12?
To fix CVE-2015-8568 in QEMU on Debian 12, update to version 1:8.1.2+ds-1 or later.
Where can I find more information about CVE-2015-8568?
You can find more information about CVE-2015-8568 in the following references: [SecurityFocus](http://www.securityfocus.com/bid/79721), [Debian Security Advisory](http://www.debian.org/security/2016/dsa-3471), [Gentoo Linux Security Advisory](https://security.gentoo.org/glsa/201602-01).
What is the CWE ID associated with CVE-2015-8568?
The CWE ID associated with CVE-2015-8568 is CWE-772.