CVE-2015-8613: Buffer Overflow
Last updated 24 July 2024
Other sources
Qemu emulator built with the SCSI MegaRAID SAS HBA emulation support is vulnerable to a stack buffer overflow issue. It occurs while processing the SCSI controller's CTRLGETINFO command. A privileged guest user could use this flaw to crash the Qemu process instance resulting in DoS.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2015-12/msg03737.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2015/12/22/1
— Red Hat
Stack-based buffer overflow in the megasasctrlgetinfo function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRLGETINFO command.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8613?
CVE-2015-8613 is a vulnerability that allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command in QEMU, when built with SCSI MegaRAID SAS HBA emulation support.
Is CVE-2015-8613 a severe vulnerability?
No, CVE-2015-8613 has a low severity level.
Which software is affected by CVE-2015-8613?
QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and various Debian versions are affected by CVE-2015-8613.
How can I fix CVE-2015-8613?
To fix CVE-2015-8613, update QEMU to a version that includes the necessary security patches.
Where can I find more information about CVE-2015-8613?
You can find more information about CVE-2015-8613 at the following references: [Security Focus](http://www.securityfocus.com/bid/79719), [Debian Security Advisory](http://www.debian.org/security/2016/dsa-3471), [Gentoo Linux Security Advisory](https://security.gentoo.org/glsa/201604-01).