First published: Thu Dec 29 2016(Updated: )
The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8818 has a severity rating that indicates it can lead to a denial of service through crashes in the guest environment.
To fix CVE-2015-8818, update QEMU to a version later than 2.3.1 where the vulnerability has been addressed.
Local privileged guest users running vulnerable versions of QEMU are affected by CVE-2015-8818.
CVE-2015-8818 is a denial of service vulnerability that can cause a crash in guest virtual machines.
QEMU versions up to and including 2.3.1 are vulnerable to CVE-2015-8818.