cbcvebase.
CVE-2015-4106
published 2015-06-03

CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain…

PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.48%
38.5th percentile
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.3+dfsg-5 (bookworm)qemu 1:2.3+dfsg-5 (bookworm)
debianxen< qemu 1:2.3+dfsg-5 (bookworm)qemu 1:2.3+dfsg-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
qemuqemu<= 2.3.1
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.