CVE-2015-8743: High severity qemu vulnerability
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAPSYSRAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.
— Launchpad
Qemu emulator built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations.
A privileged(CAPSYSRAWIO) user/process could use this flaw to leak or corrupt Qemu memory bytes(3).
Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg00050.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/01/04/2
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8743?
CVE-2015-8743 is a vulnerability in QEMU (Quick Emulator) that allows for out-of-bounds read/write access.
How does the vulnerability in CVE-2015-8743 occur?
The vulnerability in CVE-2015-8743 occurs during 'ioport' read/write operations in QEMU's NE2000 device emulation support.
What is the severity level of CVE-2015-8743?
CVE-2015-8743 has a low severity level.
Which software versions are affected by CVE-2015-8743?
QEMU versions 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, 1.0+, 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u10, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u1, 1:8.0.4+dfsg-3, and 1:8.1.0+ds-6 are affected by CVE-2015-8743.
How can I fix the vulnerability in CVE-2015-8743?
To fix the vulnerability in CVE-2015-8743, update to QEMU version 2.0.0+dfsg-2ubuntu1.22 or apply the appropriate security patches from the vendor.