CVE-2015-3214
published 2015-08-31CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might…
PriorityP338medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
1.59%
73.0th percentile
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| debian | qemu | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| debian | xen | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| lenovo | emc_px12-400r_ivx | < 1.0.10.33264 | 1.0.10.33264 |
| lenovo | emc_px12-450r_ivx | < 1.0.10.33264 | 1.0.10.33264 |
| linux | linux_kernel | <= 2.6.32 | — |
| qemu | qemu | <= 2.3.0 | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.15 | 2.0.0+dfsg-2ubuntu1.15 |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 6.9
CVE-2015-3214 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by t
Red Hat
qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
vendor_redhat·2015-06-16·CVSS 6.9
CVE-2015-3214 [MEDIUM] CWE-119 qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
An out-of-bounds memory access flaw, leading to memory corruption or possibly an information leak, was found in QEMU's pit_ioport_read() function. A privileged guest user in a QEMU guest, which had QEMU PIT emulation enabled, could potentially, in rare cases, use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process.
Statement: This issue does not affect the versions of the qemu and qemu-kvm packages as shipped with R
Debian
CVE-2015-3214: linux - The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before...
vendor_debian·2015·CVSS 6.9
CVE-2015-3214 [MEDIUM] CVE-2015-3214: linux - The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before...
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-7g3q-j68f-2fw5: The pit_ioport_read in i8254
ghsa_unreviewed·2022-05-13
CVE-2015-3214 [MEDIUM] CWE-119 GHSA-7g3q-j68f-2fw5: The pit_ioport_read in i8254
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
OSV
CVE-2015-3214: The pit_ioport_read in i8254
osv·2015-08-31·CVSS 6.9
CVE-2015-3214 [MEDIUM] CVE-2015-3214: The pit_ioport_read in i8254
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
OSV
qemu vulnerabilities
osv·2015-07-28·CVSS 6.9
CVE-2015-3214 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-5154)
Zhu Donghai dis
No detection rules found.
Bugzilla
CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
bugzilla·2018-10-15·CVSS 5.3
CVE-2018-3214 [MEDIUM] CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
An infinite loop flaw was found in the RIFF (Resource Interchange File Format) file format reader in the Sound component of OpenJDK. A specially crafted RIFF file could cause a Java application to enter an infinite loop while reading the RIFF file.
Discussion:
This issue was originally reported and fixed in 2015:
https://bugs.openjdk.java.net/browse/JDK-8135160
http://hg.openjdk.java.net/jdk9/jdk9/jdk/rev/420dd4208444
but it only got fixed in OpenJDK 9 and not backported to earlier versions at the time.
The problem was re-discovered again when fuzzing Apache Tika:
https://www.modzero.ch/modlog/archives/2018/09/20/java_bugs_with_and_without_fuzzing/index.html
---
Public now via Oracle CPU October 2018:
htt
Bugzilla
CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [epel-7]
bugzilla·2015-07-16·CVSS 6.9
CVE-2015-3214 [MEDIUM] CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [epel-7]
CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for qem
Bugzilla
CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [fedora-all]
bugzilla·2015-07-16·CVSS 6.9
CVE-2015-3214 [MEDIUM] CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [fedora-all]
CVE-2015-3214 qemu: qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2015-3214 qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
bugzilla·2015-06-09·CVSS 6.9
CVE-2015-3214 [MEDIUM] CVE-2015-3214 qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
CVE-2015-3214 qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function
Due converting PIO to the new memory read/write api we no longer provide
separate I/O region lenghts for read and write operations. As a result,
reading from PIT Mode/Command register will end with accessing
pit->channels with invalid index and potentially cause memory corruption and/or
minor information leak.
A privileged guest user in a guest with QEMU PIT emulation enabled could
potentially (tough unlikely) use this flaw to execute arbitrary code on the
host with the privileges of the hosting QEMU process. (QEMU part of the vulnerability)
A privileged guest user in a guest could potentially (tough unlikely) use this flaw to execute arbitrary code on the host. (KVM part of the vulnerability)
Acknow
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee73f656a604d5aa9df86a97102e4e462dd79924http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.33http://rhn.redhat.com/errata/RHSA-2015-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1512.htmlhttp://www.debian.org/security/2015/dsa-3348http://www.openwall.com/lists/oss-security/2015/06/25/7http://www.securityfocus.com/bid/75273http://www.securitytracker.com/id/1032598https://bugzilla.redhat.com/show_bug.cgi?id=1229640https://github.com/torvalds/linux/commit/ee73f656a604d5aa9df86a97102e4e462dd79924https://security.gentoo.org/glsa/201510-02https://support.lenovo.com/product_security/qemuhttps://support.lenovo.com/us/en/product_security/qemuhttps://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13https://www.exploit-db.com/exploits/37990/https://www.mail-archive.com/qemu-devel%40nongnu.org/msg304138.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee73f656a604d5aa9df86a97102e4e462dd79924http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.33http://rhn.redhat.com/errata/RHSA-2015-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1512.htmlhttp://www.debian.org/security/2015/dsa-3348http://www.openwall.com/lists/oss-security/2015/06/25/7http://www.securityfocus.com/bid/75273http://www.securitytracker.com/id/1032598https://bugzilla.redhat.com/show_bug.cgi?id=1229640https://github.com/torvalds/linux/commit/ee73f656a604d5aa9df86a97102e4e462dd79924https://security.gentoo.org/glsa/201510-02https://support.lenovo.com/product_security/qemuhttps://support.lenovo.com/us/en/product_security/qemuhttps://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13https://www.exploit-db.com/exploits/37990/https://www.mail-archive.com/qemu-devel%40nongnu.org/msg304138.html
2015-08-31
Published