CVE-2015-2756
published 2015-04-01CVE-2015-2756: QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.45%
36.4th percentile
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.3+dfsg-3 (bookworm) | qemu 1:2.3+dfsg-3 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-3 (bookworm) | qemu 1:2.3+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.11 | 2.0.0+dfsg-2ubuntu1.11 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.2.0~rc2-1 | 4.2.0~rc2-1 |
| xen | xen | >= 0 < 4.2.0~rc2-1 | 4.2.0~rc2-1 |
| xen | xen | >= 0 < 4.2.0~rc2-1 | 4.2.0~rc2-1 |
| xen | xen | >= 0 < 4.2.0~rc2-1 | 4.2.0~rc2-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv8.6HIGH
vendor_ubuntu8.6HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-05-13·CVSS 8.6
CVE-2015-1779 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Jason Geffner discovered that QEMU incorrectly handled the virtual floppy
driver. This issue is known as VENOM. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-3456)
Daniel P. Berrange discovered that QEMU incorrectly handled VNC websockets.
A remote attacker could use this issue to cause QEMU to consume memory,
resulting in a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-1779)
Jan Beulich discovered that QEMU, when
Red Hat
xen: unmediated PCI command register access in qemu (xsa126)
vendor_redhat·2015-03-31·CVSS 4.9
CVE-2015-2756 [MEDIUM] xen: unmediated PCI command register access in qemu (xsa126)
xen: unmediated PCI command register access in qemu (xsa126)
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Statement: This issue dos affect the xen packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterpri
Debian
CVE-2015-2756: qemu - QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to P...
vendor_debian·2015·CVSS 4.9
CVE-2015-2756 [MEDIUM] CVE-2015-2756: qemu - QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to P...
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-3)
bullseye: resolved (fixed in 1:2.3+dfsg-3)
forky: resolved (fixed in 1:2.3+dfsg-3)
sid: resolved (fixed in 1:2.3+dfsg-3)
trixie: resolved (fixed in 1:2.3+dfsg-3)
GHSA
GHSA-vw92-7fxg-964r: QEMU, as used in Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-2756 [MEDIUM] GHSA-vw92-7fxg-964r: QEMU, as used in Xen 3
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-05-13·CVSS 8.6
CVE-2015-3456 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Jason Geffner discovered that QEMU incorrectly handled the virtual floppy
driver. This issue is known as VENOM. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-3456)
Daniel P. Berrange discovered that QEMU incorrectly handled VNC websockets.
A remote attacker could use this issue to cause QEMU to consume memory,
resulting in a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-1779)
Jan Beulich discovered that QEMU, when used with Xen, didn't properly
restrict access to P
OSV
CVE-2015-2756: QEMU, as used in Xen 3
osv·2015-04-01·CVSS 4.9
CVE-2015-2756 [MEDIUM] CVE-2015-2756: QEMU, as used in Xen 3
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126) [fedora-all]
bugzilla·2015-03-31·CVSS 4.9
CVE-2015-2756 [MEDIUM] CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126) [fedora-all]
CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126)
bugzilla·2015-03-19·CVSS 4.9
CVE-2015-2756 [MEDIUM] CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126)
CVE-2015-2756 xen: unmediated PCI command register access in qemu (xsa126)
ISSUE DESCRIPTION
HVM guests are currently permitted to modify the memory and I/O decode
bits in the PCI command register of devices passed through to them.
Unless the device is an SR-IOV virtual function, subsequent accesses to
the respective MMIO or I/O port ranges would - on PCI Express devices -
lead to Unsupported Request responses. The treatment of such errors is
platform specific.
IMPACT
In the event that the platform surfaces aforementioned UR responses as
Non-Maskable Interrupts, and either the OS is configured to treat NMIs
as fatal or (e.g. via ACPI's APEI) the platform tells the OS to treat
these errors as fatal, the host would crash, leading to a Denial of
Service.
VULNERABLE SYSTEMS
Xen versions
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.nongnu.org/archive/html/qemu-devel/2015-03/msg06179.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3259http://www.securityfocus.com/bid/72577http://www.securitytracker.com/id/1031998http://www.ubuntu.com/usn/USN-2608-1http://xenbits.xen.org/xsa/advisory-126.htmlhttps://security.gentoo.org/glsa/201504-04https://support.citrix.com/article/CTX206006http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.nongnu.org/archive/html/qemu-devel/2015-03/msg06179.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3259http://www.securityfocus.com/bid/72577http://www.securitytracker.com/id/1031998http://www.ubuntu.com/usn/USN-2608-1http://xenbits.xen.org/xsa/advisory-126.htmlhttps://security.gentoo.org/glsa/201504-04https://support.citrix.com/article/CTX206006
2015-04-01
Published