CVE-2015-7295 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Qemu
Severity
5.0MEDIUMNVD
EPSS
3.6%
top 12.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 9
Latest updateMay 13
Description
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
Also affects: Debian Linux 7.0, 8.0, Fedora 21, 22