Infinite loop in QEMU - CVE-2015-5278
Published: August 5, 2020
Vulnerability identifier: #VU33991
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5278
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the ne2000_receive() function in hw/net/ne2000.c in QEMU. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
QEMU
qemu (Alpine package)
xen
Fedora
qemu (Alpine package)
xen
Fedora
How to mitigate CVE-2015-5278
Install updates from vendor's website.
QEMU - update to 2.4.0.1
qemu (Alpine package) - update to 1.6.2-r6
xen - addressed in versions 4.4.3-4.fc21, 4.5.1-9.fc22, 4.5.1-9.fc23
qemu (Alpine package) - update to 1.6.2-r6
xen - addressed in versions 4.4.3-4.fc21, 4.5.1-9.fc22, 4.5.1-9.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.html
- http://www.openwall.com/lists/oss-security/2015/09/15/2
- http://www.ubuntu.com/usn/USN-2745-1
- https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg03985.html
- https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg05832.html