CVE-2015-7295
published 2015-11-09CVE-2015-7295: hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.93%
91.2th percentile
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.4+dfsg-4 (bookworm) | qemu 1:2.4+dfsg-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qemu | qemu | <= 2.4.1 | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-4 | 1:2.4+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-4 | 1:2.4+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-4 | 1:2.4+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.4+dfsg-4 | 1:2.4+dfsg-4 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.21 | 2.0.0+dfsg-2ubuntu1.21 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw9m-9h89-prfq: hw/virtio/virtio
ghsa_unreviewed·2022-05-13
CVE-2015-7295 [MEDIUM] CWE-119 GHSA-cw9m-9h89-prfq: hw/virtio/virtio
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-12-03·CVSS 5.0
CVE-2015-7295 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Jason Wang discovered that QEMU incorrectly handled the virtio-net device.
A remote attacker could use this issue to cause guest network consumption,
resulting in a denial of service. (CVE-2015-7295)
Qinghao Tang and Ling Liu discovered that QEMU incorrectly handled the
pcnet driver when used in loopback mode. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-7504)
Ling Liu and Jason Wang discovered that QEMU incorrectly handled the
pcnet driver. A remote attacker could use this issue to cause a denial of
service, or possibl
OSV
CVE-2015-7295: hw/virtio/virtio
osv·2015-11-09·CVSS 5.0
CVE-2015-7295 [MEDIUM] CVE-2015-7295: hw/virtio/virtio
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-12-03·CVSS 5.0
CVE-2015-7295 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Jason Wang discovered that QEMU incorrectly handled the virtio-net device.
A remote attacker could use this issue to cause guest network consumption,
resulting in a denial of service. (CVE-2015-7295)
Qinghao Tang and Ling Liu discovered that QEMU incorrectly handled the
pcnet driver when used in loopback mode. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-7504)
Ling Liu and Jason Wang discovered that QEMU incorrectly handled the
pcnet driver. A remote attacker could use
Red Hat
Qemu: net: virtio-net possible remote DoS
vendor_redhat·2015-09-18·CVSS 5.0
CVE-2015-7295 [MEDIUM] CWE-772 Qemu: net: virtio-net possible remote DoS
Qemu: net: virtio-net possible remote DoS
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
A flaw has been discovered in the QEMU emulator built with Virtual Network Device(virtio-net) support. If the guest's virtio-net driver did not support big or mergeable receive buffers, an issue could occur while receiving large packets over the tuntap/ macvtap interfaces. An attacker on the local network could use this flaw to disable the guest's networking; the user could send a large number of jumbo frames to the guest, which could exhaust all receive buffers,
Debian
CVE-2015-7295: qemu - hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, w...
vendor_debian·2015·CVSS 5.0
CVE-2015-7295 [MEDIUM] CVE-2015-7295: qemu - hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, w...
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-4)
bullseye: resolved (fixed in 1:2.4+dfsg-4)
forky: resolved (fixed in 1:2.4+dfsg-4)
sid: resolved (fixed in 1:2.4+dfsg-4)
trixie: resolved (fixed in 1:2.4+dfsg-4)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169624.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169767.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169802.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2015/09/18/5http://www.openwall.com/lists/oss-security/2015/09/18/9http://www.securityfocus.com/bid/82672https://security.gentoo.org/glsa/201602-01http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169624.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169767.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169802.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2015/09/18/5http://www.openwall.com/lists/oss-security/2015/09/18/9http://www.securityfocus.com/bid/82672https://security.gentoo.org/glsa/201602-01
2015-11-09
Published