CVE-2015-8619: High severity qemu vulnerability
Last updated 24 July 2024
Other sources
Qemu emulator built with the Human Monitor Interface(HMP) support is vulnerable to an OOB write issue. It occurs while processing 'sendkey' command in hmpsendkey routine, if the command argument is longer than the 'keynamebuf' buffer size.
A user/process could use this flaw to crash the Qemu process instance resulting in DoS.
Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg02160.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2015/12/23/1
— Red Hat
The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2015-8619.
What is the severity of CVE-2015-8619?
The severity of CVE-2015-8619 is low.
How does CVE-2015-8619 affect QEMU?
CVE-2015-8619 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) in QEMU.
Which versions of QEMU are affected by CVE-2015-8619?
QEMU versions 2.0.0+dfsg-2ubuntu1.22 and 1:2.3+dfsg-5ubuntu9.2 are affected by CVE-2015-8619.
How can I fix CVE-2015-8619 in QEMU?
To fix CVE-2015-8619 in QEMU, you should update to a version that includes the provided remedy.