3.5

CVE-2015-6815

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
QemuQemu Version < 2.4.0.1
FedoraprojectFedora Version21
FedoraprojectFedora Version22
FedoraprojectFedora Version23
NovellSuse Linux Enterprise Debuginfo Version11.0 Updatesp3
NovellSuse Linux Enterprise Debuginfo Version11.0 Updatesp4
NovellSuse Linux Enterprise Desktop Version11.0 Updatesp3
NovellSuse Linux Enterprise Desktop Version11.0 Updatesp4
NovellSuse Linux Enterprise Server Version11.0 Updatesp3
NovellSuse Linux Enterprise Server Version11.0 Updatesp4
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.04
RedhatOpenstack Version5.0
RedhatOpenstack Version6.0
RedhatOpenstack Version7.0
RedhatEnterprise Linux Version5.0
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version7.0
XenXen Version4.4.3
XenXen Version4.5.1
AristaEos Version4.12
AristaEos Version4.13
AristaEos Version4.14
AristaEos Version4.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.25% 0.84
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 2.7 5.1 2.9
AV:A/AC:L/Au:S/C:N/I:N/A:P
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://bugzilla.redhat.com/show_bug.cgi?id=1260076
Patch
Third Party Advisory
Issue Tracking