6.9
CVE-2015-3214
- EPSS 1.59%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 2.6.32
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Lenovo ≫ Emc Px12-400r Ivx Version < 1.0.10.33264
Lenovo ≫ Emc Px12-450r Ivx Version < 1.0.10.33264
Redhat ≫ Virtualization Version 3.0
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.1
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.2
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.3
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.4
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.5
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.6
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.7
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.1_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.2_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.3_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.4_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.5_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.6_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.7_ppc64
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Eus Version 7.1
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 7.7
Redhat ≫ Enterprise Linux Server From Rhui Version 7.0
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.59% | 0.725 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.33
https://security.gentoo.org/glsa/201510-02
https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
http://rhn.redhat.com/errata/RHSA-2015-1507.html
http://rhn.redhat.com/errata/RHSA-2015-1508.html
http://rhn.redhat.com/errata/RHSA-2015-1512.html
http://www.debian.org/security/2015/dsa-3348
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee73f656a604d5aa9df86a97102e4e462dd79924
http://www.openwall.com/lists/oss-security/2015/06/25/7
http://www.securityfocus.com/bid/75273
http://www.securitytracker.com/id/1032598
https://bugzilla.redhat.com/show_bug.cgi?id=1229640
https://github.com/torvalds/linux/commit/ee73f656a604d5aa9df86a97102e4e462dd79924
https://support.lenovo.com/product_security/qemu
https://support.lenovo.com/us/en/product_security/qemu
https://www.exploit-db.com/exploits/37990/
https://www.mail-archive.com/qemu-devel%40nongnu.org/msg304138.html