PT-2015-3283 · Qemu+3 · Qemu+3
Qinghao Tang
·
Published
2015-12-31
·
Updated
2024-06-15
·
CVE-2015-8613
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
QEMU (affected versions not specified)
Description
The issue is related to a stack-based buffer overflow in the
megasas ctrl get info function in QEMU, specifically when it is built with SCSI MegaRAID SAS HBA emulation support. This allows local guest users to cause a denial of service by crashing the QEMU instance via a crafted SCSI controller CTRL GET INFO command. The exploitation of this issue can lead to a service disruption.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Qemu
Suse
Ubuntu