CVE-2015-8666: Buffer Overflow
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Other sources
Qemu emulator built with the Q35 chipset based pc system emulator is vulnerable to a heap based buffer overflow. It occurs during VM guest migration, as more(8 bytes) data is moved than allocated memory area.
A privileged guest user could use this issue to corrupt the VM guest image, potentially leading to a DoS. This issue affects q35 machine types.
Upstream fix: ------------- -> git.qemu.org/?p=qemu.git;a=commit;h=d9a3b33d2c9f996537b7f1d0246dee2d0120cefb
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2015/12/24/1
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2015-8666?
CVE-2015-8666 is a vulnerability in QEMU that allows for a heap-based buffer overflow.
How does CVE-2015-8666 affect QEMU?
CVE-2015-8666 affects QEMU when it is built with the Q35-chipset-based PC system emulator.
What is the severity of CVE-2015-8666?
CVE-2015-8666 has a low severity.
Which software versions are affected by CVE-2015-8666?
QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and several other Debian versions are affected by CVE-2015-8666.
How can CVE-2015-8666 be fixed?
To fix CVE-2015-8666, update QEMU to version 2.0.0+dfsg-2ubuntu1.22 or apply the appropriate security patch for the specific Debian version being used.