Infinite loop in QEMU - CVE-2015-6815
Published: August 5, 2020
Vulnerability identifier: #VU33992
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-6815
CWE-ID: CWE-835
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the process_tx_desc() function in hw/net/e1000.c in QEMU. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
QEMU
qemu (Alpine package)
xen
Fedora
qemu (Alpine package)
xen
Fedora
How to mitigate CVE-2015-6815
Install updates from vendor's website.
QEMU - update to 2.4.0.1
qemu (Alpine package) - update to 1.6.2-r6
xen - addressed in versions 4.4.3-4.fc21, 4.5.1-9.fc22, 4.5.1-9.fc23
qemu (Alpine package) - update to 1.6.2-r6
xen - addressed in versions 4.4.3-4.fc21, 4.5.1-9.fc22, 4.5.1-9.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.html
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html
- http://www.openwall.com/lists/oss-security/2015/09/04/4
- http://www.openwall.com/lists/oss-security/2015/09/05/5
- http://www.ubuntu.com/usn/USN-2745-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1260076
- https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg01199.html
- https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg05832.html