Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian DSA-3362-1 Critical: qemu-kvm Denial Of Service Attacks

debian
Calendar Grey September 18, 2015
Debian Logo
Ubuntu Security Notice USN-4183-1 highlights severe vulnerabilities in libjpeg-turbo affecting system stability on ARM devices.
Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware

Summary

CVE-2015-5278

Qinghao Tang of QIHU 360 Inc. discovered an infinite loop issue in
the NE2000 NIC emulation. A privileged guest user could use this
flaw to mount a denial of service (QEMU process crash).

CVE-2015-5279

Qinghao Tang of QIHU 360 Inc. discovered a heap buffer overflow flaw
in the NE2000 NIC emulation. A privileged guest user could use this
flaw to mount a denial of service (QEMU process crash), or
potentially to execute arbitrary code on the host with the
privileges of the hosting QEMU process.

CVE-2015-6815

Qinghao Tang of QIHU 360 Inc. discovered an infinite loop issue in
the e1000 NIC emulation. A privileged guest user could use this flaw
to mount a denial of service (QEMU process crash).

CVE-2015-6855

Qinghao Tang of QIHU 360 Inc. discovered a flaw in the IDE
subsystem in QEMU occurring while executing IDE's
WIN_READ_NATIVE_MAX command to determine the maximum size of a
drive. A privileged guest user could use this flaw to mou...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: qemu-kvm
CVE ID: CVE-2015-5278 CVE-2015-5279 CVE-2015-6815 CVE-2015-6855

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here