CVE-2015-4106
published 2015-06-03CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.48%
38.5th percentile
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qemu | qemu | <= 2.3.1 | — |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of serv
Red Hat
xen: unmediated PCI register access in qemu (xsa-131)
vendor_redhat·2015-06-02·CVSS 4.6
CVE-2015-4106 [MEDIUM] xen: unmediated PCI register access in qemu (xsa-131)
xen: unmediated PCI register access in qemu (xsa-131)
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
Statement: This issue does affect then Xen packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Debian
CVE-2015-4106: qemu - QEMU does not properly restrict write access to the PCI config space for certain...
vendor_debian·2015·CVSS 4.6
CVE-2015-4106 [MEDIUM] CVE-2015-4106: qemu - QEMU does not properly restrict write access to the PCI config space for certain...
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-5)
bullseye: resolved (fixed in 1:2.3+dfsg-5)
forky: resolved (fixed in 1:2.3+dfsg-5)
sid: resolved (fixed in 1:2.3+dfsg-5)
trixie: resolved (fixed in 1:2.3+dfsg-5)
Citrix
Citrix Security Bulletin CTX201145
vendor_citrix·CVSS 4.6
CVE-2015-4106 [MEDIUM] Citrix Security Bulletin CTX201145
Citrix Security Bulletin CTX201145
CVE References: CVE-2015-4106, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX206006
vendor_citrix·CVSS 4.6
CVE-2015-4106 [MEDIUM] Citrix Security Bulletin CTX206006
Citrix Security Bulletin CTX206006
CVE References: CVE-2015-4106, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-53r2-p844-jg4x: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to g
ghsa_unreviewed·2022-05-13
CVE-2015-4106 [MEDIUM] CWE-863 GHSA-53r2-p844-jg4x: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to g
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of service. This issue only applied to Ubuntu 14.04
LTS, U
OSV
CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to g
osv·2015-06-03·CVSS 4.6
CVE-2015-4106 [MEDIUM] CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to g
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74949http://www.securitytracker.com/id/1032467http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-131.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74949http://www.securitytracker.com/id/1032467http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-131.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006
2015-06-03
Published