cbcvebase.
CVE-2015-3214
published 2015-08-31

CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
EXPLOIT
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos
aristaeos
aristaeos
aristaeos
debiandebian_linux
debiandebian_linux
debianlinux< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianqemu< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianxen< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
lenovoemc_px12-400r_ivx< 1.0.10.332641.0.10.33264
lenovoemc_px12-450r_ivx< 1.0.10.332641.0.10.33264
linuxlinux_kernel<= 2.6.32
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.152.0.0+dfsg-2ubuntu1.15
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_compute_node_eus

CVSS provenance

nvd6.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM