CVE-2015-5158
published 2016-04-12CVE-2015-5158: Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.43%
35.5th percentile
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.15 | 2.0.0+dfsg-2ubuntu1.15 |
| qemu | qemu | >= 2.2.0 < 2.4.0 | 2.4.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx3q-72jh-pq5j: Stack-based buffer overflow in hw/scsi/scsi-bus
ghsa_unreviewed·2022-05-13
CVE-2015-5158 [MEDIUM] CWE-787 GHSA-gx3q-72jh-pq5j: Stack-based buffer overflow in hw/scsi/scsi-bus
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
OSV
CVE-2015-5158: Stack-based buffer overflow in hw/scsi/scsi-bus
osv·2016-04-12·CVSS 5.5
CVE-2015-5158 [MEDIUM] CVE-2015-5158: Stack-based buffer overflow in hw/scsi/scsi-bus
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
OSV
qemu vulnerabilities
osv·2015-07-28·CVSS 6.9
CVE-2015-3214 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-5154)
Zhu Donghai dis
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 6.9
CVE-2015-3214 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled PIT emulation. In a
non-default configuration, a malicious guest could use this issue to cause
a denial of service, or possibly execute arbitrary code on the host as the
user running the QEMU process. In the default installation, when QEMU is
used with libvirt, attackers would be isolated by the libvirt AppArmor
profile. (CVE-2015-3214)
Kevin Wolf discovered that QEMU incorrectly handled processing ATAPI
commands. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by t
Red Hat
Qemu: scsi stack buffer overflow
vendor_redhat·2015-07-22·CVSS 5.5
CVE-2015-5158 [MEDIUM] CWE-121 Qemu: scsi stack buffer overflow
Qemu: scsi stack buffer overflow
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
A flaw has been discovered in the QEMU emulator built with SCSI-device emulation support. The emulator is vulnerable to a stack buffer overflow issue, which can occur while parsing a SCSI command descriptor block with an invalid operation code. A privileged(CAP_SYS_RAWIO) user inside a guest could use this flaw to crash the QEMU instance resulting in a denial-of-service (DoS) attack.
Statement: This issue does not affect the versions of kvm and xen packages as shipped with Red Hat Enterprise Linu
Debian
CVE-2015-5158: qemu - Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-...
vendor_debian·2015·CVSS 5.5
CVE-2015-5158 [MEDIUM] CVE-2015-5158: qemu - Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-...
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.4+dfsg-1a)
trixie: resolved (fixed in 1:2.4+dfsg-1a)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5158 Qemu: scsi stack buffer overflow [fedora-all]
bugzilla·2015-07-23·CVSS 5.5
CVE-2015-5158 [MEDIUM] CVE-2015-5158 Qemu: scsi stack buffer overflow [fedora-all]
CVE-2015-5158 Qemu: scsi stack buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2015-5158 Qemu: scsi stack buffer overflow
bugzilla·2015-07-17·CVSS 5.5
CVE-2015-5158 [MEDIUM] CVE-2015-5158 Qemu: scsi stack buffer overflow
CVE-2015-5158 Qemu: scsi stack buffer overflow
Qemu emulator built with the SCSI device emulation support is vulnerable to a
stack buffer overflow issue. It could occur while parsing SCSI command
descriptor block with an invalid operation code.
A privileged(CAP_SYS_RAWIO) user inside guest could use this flaw to crash
the Qemu instance resulting in DoS.
Upstream fix:
-> git.qemu.org/?p=qemu.git;a=commit;h=c170aad8b057223b1139d72e5ce7acceafab4fa9
Reference:
-> http://www.openwall.com/lists/oss-security/2015/07/23/6
Discussion:
Statement:
This issue does not affect the versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue does not affect the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7.
This issue does not affec
http://www.securityfocus.com/bid/76016http://www.securitytracker.com/id/1033095https://lists.nongnu.org/archive/html/qemu-devel/2015-07/msg04558.htmlhttps://security.gentoo.org/glsa/201510-02http://www.securityfocus.com/bid/76016http://www.securitytracker.com/id/1033095https://lists.nongnu.org/archive/html/qemu-devel/2015-07/msg04558.htmlhttps://security.gentoo.org/glsa/201510-02
2016-04-12
Published