cbcvebase.
CVE-2015-6855
published 2015-11-06

CVE-2015-6855: hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.4+dfsg-2 (bookworm)qemu 1:2.4+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
qemuqemu<= 2.4.1
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 1:2.4+dfsg-21:2.4+dfsg-2
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.192.0.0+dfsg-2ubuntu1.19
suselinux_enterprise_desktop
suselinux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH