CVE-2015-8745: Medium severity qemu vulnerability
Last updated 24 July 2024
Other sources
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAPSYSRAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
— Launchpad
Qemu emulator built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers(IMR).
A privileged(CAPSYSRAWIO) guest user could use this flaw to crash the Qemu process instance resulting in DoS.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=c6048f849c7e3f009786df76206e895
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/01/04/7
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8745?
CVE-2015-8745 is a vulnerability in QEMU, specifically in the VMWARE VMXNET3 paravirtual NIC emulator support, that could allow a privileged guest user to crash the QEMU process instance resulting in a denial-of-service (DoS) attack.
How severe is CVE-2015-8745?
CVE-2015-8745 has a severity rating of 5.5, which is classified as medium.
Which software versions are affected by CVE-2015-8745?
QEMU versions up to and including 2.0.0+dfsg-2ubuntu1.22, 1:2.3+dfsg-5ubuntu9.2, and up to version 2.4.1 are affected. Debian Linux version 8.0 and certain versions of qemu package in Debian and Ubuntu are also affected.
How can I fix CVE-2015-8745?
To fix CVE-2015-8745, update QEMU to version 2.0.0+dfsg-2ubuntu1.22 or later, 1:2.3+dfsg-5ubuntu9.2 or later, or QEMU version 2.4.2 or later. For Debian and Ubuntu systems, follow the remediation steps provided in the respective security advisories.
Where can I find more information about CVE-2015-8745?
You can find more information about CVE-2015-8745 on the following references: - [SecurityTracker](http://www.securitytracker.com/id/1034575) - [SecurityFocus](http://www.securityfocus.com/bid/79822) - [Debian Security Advisory](http://www.debian.org/security/2016/dsa-3471)