CVE-2015-8744: Input Validation
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAPSYSRAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
— Launchpad
Qemu emulator built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packets smaller than 22 bytes.
A privileged(CAPSYSRAWIO) guest user could use this flaw to crash the Qemu process instance resulting in DoS.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=a7278b36fcab9af469563bd7b
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/01/04/6
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8744?
CVE-2015-8744 is a vulnerability in QEMU (Quick Emulator) that occurs when a guest sends a Layer-2 packet smaller than 22 bytes, resulting in a crash issue and possible DoS.
How severe is CVE-2015-8744?
CVE-2015-8744 is considered to be a low severity vulnerability.
Which software is affected by CVE-2015-8744?
QEMU (Quick Emulator) versions 2.0.0 up to exclusive 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and other versions listed in the vulnerability description are affected.
How can CVE-2015-8744 be fixed?
To fix CVE-2015-8744, update QEMU to version 2.0.0+dfsg-2ubuntu1.22 or apply the appropriate security patches for other affected versions.
Where can I find more information about CVE-2015-8744?
You can find more information about CVE-2015-8744 on the following websites: SecurityTracker (http://www.securitytracker.com/id/1034576), SecurityFocus (http://www.securityfocus.com/bid/79821), and Debian Security Advisory (http://www.debian.org/security/2016/dsa-3471).