CVE-2019-15034: Buffer Overflow
Published Mar 10, 2020
·Updated
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
Affected Software
2 affected componentsFixes available
Qemu Qemu=4.0.0
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Event History
Mar 10, 2020
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:19 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·11:28 PM
RemedyDescriptionSeverityAffected Software
Feb 24, 2026
Data Sourced
via Debian·11:32 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-15034?
CVE-2019-15034 is a vulnerability in QEMU 4.0.0 that allows a buffer overflow due to insufficient PCI config space allocation.
2
How severe is CVE-2019-15034?
CVE-2019-15034 has a severity score of 5.8, which is considered medium.
3
How does CVE-2019-15034 affect QEMU?
CVE-2019-15034 affects QEMU 4.0.0, allowing a buffer overflow involving the PCIe extended config space.
4
Is there a fix available for CVE-2019-15034?
Yes, Debian and Ubuntu have released updates to address CVE-2019-15034. Please refer to the provided references for more information.
5
Where can I find more information about CVE-2019-15034?
You can find more information about CVE-2019-15034 at the provided references.