PT-2017-1611 · Qemu+1 · Qemu+1
Zx2C4
·
Published
2015-12-21
·
Updated
2017-03-27
·
CVE-2015-8556
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 2.5.0-r1
Gentoo QEMU package before 2.5.0-r1
Description
The issue is caused by synchronization errors when using a shared resource in the QEMU hardware emulator. Exploitation of this issue may allow a remote attacker to cause a denial of service or elevate privileges in the guest operating system.
Recommendations
For QEMU versions prior to 2.5.0-r1, update to version 2.5.0-r1 or later to resolve the issue.
For the Gentoo QEMU package before 2.5.0-r1, update to version 2.5.0-r1 or later to resolve the issue.
Exploit
Fix
LPE
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Qemu