cbcvebase.
CVE-2015-4106
published 2015-06-03

CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain…

medium4.6CVSS 3.1
AVLACLAuNCPIPAP
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.3+dfsg-5 (bookworm)qemu 1:2.3+dfsg-5 (bookworm)
debianxen< qemu 1:2.3+dfsg-5 (bookworm)qemu 1:2.3+dfsg-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
qemuqemu<= 2.3.1
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5

CVSS provenance

nvd4.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH