CVE-2015-6855
published 2015-11-06CVE-2015-6855: hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.50%
87.9th percentile
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.4+dfsg-2 (bookworm) | qemu 1:2.4+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qemu | qemu | <= 2.4.1 | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-2 | 1:2.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-2 | 1:2.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-2 | 1:2.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-2 | 1:2.4+dfsg-2 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.19 | 2.0.0+dfsg-2ubuntu1.19 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-09-24·CVSS 6.5
CVE-2015-5239 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lian Yihan discovered that QEMU incorrectly handled certain payload
messages in the VNC display driver. A malicious guest could use this issue
to cause the QEMU process to hang, resulting in a denial of service. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-5239)
Qinghao Tang discovered that QEMU incorrectly handled receiving certain
packets in the NE2000 network driver. A malicious guest could use this
issue to cause the QEMU process to hang, resulting in a denial of service.
(CVE-2015-5278)
Qinghao Tang discovered that QEMU incorrectly handled receiving certain
packets in the NE2000 network driver. A malicious guest could use this
issue to cause a denial of service, or possibl
Red Hat
Qemu: ide: divide by zero issue
vendor_redhat·2015-09-09·CVSS 7.5
CVE-2015-6855 [HIGH] CWE-369 Qemu: ide: divide by zero issue
Qemu: ide: divide by zero issue
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
It has been discovered that a QEMU emulator built with IDE disk and CD/DVD-ROM emulation support is vulnerable to a divide-by-zero issue. The flaw could occur when executing IDE's WIN_READ_NATIVE_MAX command to determine the maximum size of a drive. A privileged user inside the guest could use this flaw to crash the QEMU instance, resulting in a denial of service.
Statement: This issue affects the versions of kvm and xen p
Debian
CVE-2015-6855: qemu - hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATA...
vendor_debian·2015·CVSS 7.5
CVE-2015-6855 [HIGH] CVE-2015-6855: qemu - hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATA...
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-2)
bullseye: resolved (fixed in 1:2.4+dfsg-2)
forky: resolved (fixed in 1:2.4+dfsg-2)
sid: resolved (fixed in 1:2.4+dfsg-2)
trixie: resolved (fixed in 1:2.4+dfsg-2)
GHSA
GHSA-8gcq-wcj5-xgq6: hw/ide/core
ghsa_unreviewed·2022-05-13
CVE-2015-6855 [HIGH] CWE-369 GHSA-8gcq-wcj5-xgq6: hw/ide/core
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
OSV
CVE-2015-6855: hw/ide/core
osv·2015-11-06·CVSS 7.5
CVE-2015-6855 [HIGH] CVE-2015-6855: hw/ide/core
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-09-24·CVSS 6.5
CVE-2015-5239 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Lian Yihan discovered that QEMU incorrectly handled certain payload
messages in the VNC display driver. A malicious guest could use this issue
to cause the QEMU process to hang, resulting in a denial of service. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-5239)
Qinghao Tang discovered that QEMU incorrectly handled receiving certain
packets in the NE2000 network driver. A malicious guest could use this
issue to cause the QEMU process to hang, resulting in a denial of service.
(CVE-2015-5278)
Qinghao Tang discovered that QEMU incorrectly handled receiving certain
packets in the NE2000 network driver. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user ru
No detection rules found.
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168602.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169036.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169327.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169341.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167369.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.htmlhttp://www.debian.org/security/2015/dsa-3361http://www.debian.org/security/2015/dsa-3362http://www.openwall.com/lists/oss-security/2015/09/10/1http://www.openwall.com/lists/oss-security/2015/09/10/2http://www.securityfocus.com/bid/76691http://www.ubuntu.com/usn/USN-2745-1https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg02479.htmlhttps://security.gentoo.org/glsa/201602-01https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168602.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169036.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169327.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169341.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167369.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.htmlhttp://www.debian.org/security/2015/dsa-3361http://www.debian.org/security/2015/dsa-3362http://www.openwall.com/lists/oss-security/2015/09/10/1http://www.openwall.com/lists/oss-security/2015/09/10/2http://www.securityfocus.com/bid/76691http://www.ubuntu.com/usn/USN-2745-1https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg02479.htmlhttps://security.gentoo.org/glsa/201602-01https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14
2015-11-06
Published