cbcvebase.
CVE-2015-6815
published 2020-01-31

CVE-2015-6815: The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which…

PriorityP413low3.5CVSS 3.1
AVAACLPRLUINSUCNINAL
EPSS
0.98%
58.3th percentile
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos
aristaeos
aristaeos
aristaeos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianqemu< qemu 1:2.4+dfsg-2 (bookworm)qemu 1:2.4+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
novellsuse_linux_enterprise_debuginfo
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_software_development_kit
novellsuse_linux_enterprise_software_development_kit
qemuqemu< 2.4.0.12.4.0.1
qemuqemu
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.192.0.0+dfsg-2ubuntu1.19

CVSS provenance

nvdv3.13.5LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.