Buffer overflow in QEMU - CVE-2015-5745
Published: August 5, 2020
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the hypervisor system.
The vulnerability exists due to a boundary error in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU. A remote user can pass a specially crafted virtio control message, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
qemu
xen
How to mitigate CVE-2015-5745
qemu - addressed in versions 2.1.3-9.fc21, 2.3.0-7.fc22, 2.3.1-1.fc22, 2.4.0-0.2.rc4.fc23, 2.4.0-1.fc23
xen - addressed in versions 4.4.3-4.fc21, 4.5.1-9.fc22, 4.5.1-9.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.html
- http://www.openwall.com/lists/oss-security/2015/08/06/3
- http://www.openwall.com/lists/oss-security/2015/08/06/5
- https://github.com/qemu/qemu/commit/7882080388be5088e72c425b02223c02e6cb4295
- https://lists.gnu.org/archive/html/qemu-devel/2015-07/msg05458.html