PT-2015-3283 · Qemu+3 · Qemu+3

Qinghao Tang

·

Published

2015-12-31

·

Updated

2024-06-15

·

CVE-2015-8613

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to a stack-based buffer overflow in the megasas ctrl get info function in QEMU, specifically when it is built with SCSI MegaRAID SAS HBA emulation support. This allows local guest users to cause a denial of service by crashing the QEMU instance via a crafted SCSI controller CTRL GET INFO command. The exploitation of this issue can lead to a service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1565
BDU:2017-01032
CVE-2015-8613
DSA-3471-1
MGASA-2016-0023
OPENSUSE-SU-2016_0914-1
OPENSUSE-SU-2016_0995-1
OPENSUSE-SU-2016_1750-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1703-1
SUSE-SU-2016:1785-1
USN-2891-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu