cbcvebase.
CVE-2015-3214
published 2015-08-31

CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might…

PriorityP338medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
1.59%
73.0th percentile
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos
aristaeos
aristaeos
aristaeos
debiandebian_linux
debiandebian_linux
debianlinux< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianqemu< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianxen< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
lenovoemc_px12-400r_ivx< 1.0.10.332641.0.10.33264
lenovoemc_px12-450r_ivx< 1.0.10.332641.0.10.33264
linuxlinux_kernel<= 2.6.32
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.152.0.0+dfsg-2ubuntu1.15
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.