Heap-based buffer overflow in QEMU - CVE-2015-5154
Published: August 12, 2015 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled,. A remote attacker can use unspecified ATAPI commands. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
SUSE Linux
qemu (Alpine package)
xen (Alpine package)
qemu
app-emulation/qemu
xen
How to mitigate CVE-2015-5154
xen (Alpine package) - update to 4.5.1-r2
qemu - addressed in versions 2.0.0-1.el7.6, 2.1.3-9.fc21, 2.3.0-7.fc22, 2.3.1-1.fc22, 2.4.0-0.2.rc4.fc23, 2.4.0-1.fc23
app-emulation/qemu - update to 2.3.0-r4
xen - addressed in versions 4.4.2-9.fc21, 4.5.1-5.fc22, 4.5.1-5.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163472.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163658.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163681.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html
- http://rhn.redhat.com/errata/RHSA-2015-1507.html
- http://rhn.redhat.com/errata/RHSA-2015-1508.html
- http://rhn.redhat.com/errata/RHSA-2015-1512.html
- http://support.citrix.com/article/CTX201593
- http://www.debian.org/security/2015/dsa-3348
- http://www.securityfocus.com/bid/76048
- http://www.securitytracker.com/id/1033074
- http://xenbits.xen.org/xsa/advisory-138.html
- https://security.gentoo.org/glsa/201510-02
- https://security.gentoo.org/glsa/201604-03
Related Security Bulletins
- Heap-based buffer overflow in QEMU
- SUSE Linux update for kvm
- SUSE Linux update for kvm
- SUSE Linux update for kvm
- SUSE Linux update for xen
- SUSE Linux update for kvm
- SUSE Linux update for xen
- SUSE Linux update for xen
- Heap-based buffer overflow in qemu (Alpine package)
- Heap-based buffer overflow in xen (Alpine package)
- SUSE Linux update for Xen
- SUSE Linux update for xen
- Gentoo update for QEMU
- Fedora 22 update for xen
- Fedora 23 update for xen
- Fedora 21 update for xen
- Fedora 23 update for qemu
- Fedora 22 update for qemu
- Fedora 21 update for qemu
- Fedora 23 update for qemu
- Fedora 22 update for qemu
- Fedora EPEL 7 update for qemu