CVE-2015-3209
published 2015-06-15CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set…
PriorityP353high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
9.67%
95.0th percentile
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.3+dfsg-6 (bookworm) | qemu 1:2.3+dfsg-6 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-6 (bookworm) | qemu 1:2.3+dfsg-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| juniper | junos_space | <= 15.1 | — |
| qemu | qemu | <= 2.3.1 | — |
| qemu | qemu | >= 0 < 1:2.3+dfsg-6 | 1:2.3+dfsg-6 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-6 | 1:2.3+dfsg-6 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-6 | 1:2.3+dfsg-6 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-6 | 1:2.3+dfsg-6 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.13 | 2.0.0+dfsg-2ubuntu1.13 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8hq-r3jp-2m27: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPA
ghsa_unreviewed·2022-05-13
CVE-2015-3209 [HIGH] CWE-787 GHSA-f8hq-r3jp-2m27: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPA
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
OSV
CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPA
osv·2015-06-15·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPA
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of service. This issue only applied to Ubuntu 14.04
LTS, U
Red Hat
qemu: pcnet: multi-tmd buffer overflow in the tx path
vendor_redhat·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] CWE-119 qemu: pcnet: multi-tmd buffer overflow in the tx path
qemu: pcnet: multi-tmd buffer overflow in the tx path
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
A flaw was found in the way QEMU's AMD PCnet Ethernet emulation handled multi-TMD packets with a length above 4096 bytes. A privileged guest user in a guest with an AMD PCNet ethernet card enabled could potentially use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process.
Statement: This issue does not affect the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 7 as they do not enable the pcnet backend driver.
This issue does not affect the Red Hat Enterp
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of serv
Debian
CVE-2015-3209: qemu - Heap-based buffer overflow in the PCNET controller in QEMU allows remote attacke...
vendor_debian·2015·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209: qemu - Heap-based buffer overflow in the PCNET controller in QEMU allows remote attacke...
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-6)
bullseye: resolved (fixed in 1:2.3+dfsg-6)
forky: resolved (fixed in 1:2.3+dfsg-6)
sid: resolved (fixed in 1:2.3+dfsg-6)
trixie: resolved (fixed in 1:2.3+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3209 xen: qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
bugzilla·2015-06-11·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209 xen: qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
CVE-2015-3209 xen: qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
bugzilla·2015-06-11·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [epel-7]
bugzilla·2015-06-11·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [epel-7]
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for qemu: see blocks bug list fo
Bugzilla
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path
bugzilla·2015-05-28·CVSS 7.5
CVE-2015-3209 [HIGH] CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path
CVE-2015-3209 qemu: pcnet: multi-tmd buffer overflow in the tx path
A flaw was found in the way QEMU's AMD PCnet Ethernet emulation handled multi-TMD packet with length above 4096 bytes. 4096 is the maximum length per TMD and it is also currently the size of the relay buffer pcnet driver uses for sending the packet data to QEMU for further processing. With packet spanning multiple TMDs it can happen that the overall packet size will be bigger than sizeof(buffer), which results in memory corruption.
A privileged guest user in a guest with AMD PCNet ethernet card enabled could potentially use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process.
Upstream fix:
-> git.qemu.org/?p=qemu.git;a=commit;h=9f7c594c006289ad41169b854d70f5da6e400a2a
Acknow
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160669.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160677.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1087.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1088.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1089.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1189.htmlhttp://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3285http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75123http://www.securitytracker.com/id/1032545http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-135.htmlhttps://kb.juniper.net/JSA10783https://security.gentoo.org/glsa/201510-02https://security.gentoo.org/glsa/201604-03https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160669.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160677.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1087.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1088.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1089.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1189.htmlhttp://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3285http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75123http://www.securitytracker.com/id/1032545http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-135.htmlhttps://kb.juniper.net/JSA10783https://security.gentoo.org/glsa/201510-02https://security.gentoo.org/glsa/201604-03https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
2015-06-15
Published