CVE-2015-5165
published 2015-08-12CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap…
PriorityP352critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
13.29%
96.0th percentile
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| arista | eos | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| debian | xen | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | linux | — | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.17 | 2.0.0+dfsg-2ubuntu1.17 |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-764w-ch2j-96hf: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4
ghsa_unreviewed·2022-05-13
CVE-2015-5165 [HIGH] CWE-908 GHSA-764w-ch2j-96hf: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-08-27·CVSS 4.9
CVE-2014-9718 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
It was discovered that QEMU incorrectly handled a PRDT with zero complete
sectors in the IDE functionality. A malicious guest could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-9718)
Donghai Zhu discovered that QEMU incorrectly handled the RTL8139 driver.
A malicious guest could possibly use this issue to read sensitive
information from arbitrary host memory. (CVE-2015-5165)
Donghai Zhu discovered that QEMU incorrectly handled unplugging emulated
block devices. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, at
OSV
CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4
osv·2015-08-12·CVSS 9.3
CVE-2015-5165 [CRITICAL] CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-08-27·CVSS 4.9
CVE-2014-9718 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled a PRDT with zero complete
sectors in the IDE functionality. A malicious guest could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-9718)
Donghai Zhu discovered that QEMU incorrectly handled the RTL8139 driver.
A malicious guest could possibly use this issue to read sensitive
information from arbitrary host memory. (CVE-2015-5165)
Donghai Zhu discovered that QEMU incorrectly handled unplugging emulated
block devices. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the defau
Red Hat
Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
vendor_redhat·2015-08-03·CVSS 9.3
CVE-2015-5165 [CRITICAL] CWE-456 Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
An information leak flaw was found in the way QEMU's RTL8139 emulation implementation processed network packets under RTL8139 controller's C+ mode of operation. An unprivileged guest user could use this flaw to read up to 65 KB of uninitialized QEMU heap memory.
Statement: This issue affects the versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7.
This issue affects the Red Hat Enterprise Linu
Debian
CVE-2015-5165: qemu - The C+ mode offload emulation in the RTL8139 network card device model in QEMU, ...
vendor_debian·2015·CVSS 9.3
CVE-2015-5165 [CRITICAL] CVE-2015-5165: qemu - The C+ mode offload emulation in the RTL8139 network card device model in QEMU, ...
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.4+dfsg-1a)
trixie: resolved (fixed in 1:2.4+dfsg-1a)
No detection rules found.
Bugzilla
CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
bugzilla·2015-08-03·CVSS 9.3
CVE-2015-5165 [CRITICAL] CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2015-5165 xen: Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
bugzilla·2015-08-03·CVSS 9.3
CVE-2015-5165 [CRITICAL] CVE-2015-5165 xen: Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
CVE-2015-5165 xen: Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
bugzilla·2015-07-30·CVSS 9.3
CVE-2015-5165 [CRITICAL] CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
Qemu emulator built with the RTL8139 emulation support is vulnerable to an
information leakage flaw. It could occur while processing network packets
under RTL8139 controller's C+ mode of operation.
A guest user could use this flaw to read uninitialised Qemu heap memory upto
65K bytes.
Upstream fix:
-> http://git.qemu.org/?p=qemu.git;a=commit;h=2a3612ccc1fa9cea77bd193afbfe21c77e7e91ef
Reference:
-> http://www.openwall.com/lists/oss-security/2015/08/03/4
Discussion:
Statement:
This issue affects the versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7.
This issue
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1674.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1683.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1739.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1740.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1793.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1833.htmlhttp://support.citrix.com/article/CTX201717http://www.debian.org/security/2015/dsa-3348http://www.debian.org/security/2015/dsa-3349http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76153http://www.securitytracker.com/id/1033176http://xenbits.xen.org/xsa/advisory-140.htmlhttps://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1674.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1683.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1739.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1740.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1793.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1833.htmlhttp://support.citrix.com/article/CTX201717http://www.debian.org/security/2015/dsa-3348http://www.debian.org/security/2015/dsa-3349http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76153http://www.securitytracker.com/id/1033176http://xenbits.xen.org/xsa/advisory-140.htmlhttps://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
2015-08-12
Published