CVE-2015-7504
published 2017-10-16CVE-2015-7504: Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash)…
PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.64%
46.8th percentile
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.5+dfsg-1 (bookworm) | qemu 1:2.5+dfsg-1 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-13_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | <= 2.4.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:2.5+dfsg-1 | 1:2.5+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-1 | 1:2.5+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-1 | 1:2.5+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-1 | 1:2.5+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.21 | 2.0.0+dfsg-2ubuntu1.21 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a
vendor_msrc·2017-10-10·CVSS 8.8
CVE-2015-7504 [HIGH] CWE-787 Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional produc
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-12-03·CVSS 5.0
CVE-2015-7295 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Jason Wang discovered that QEMU incorrectly handled the virtio-net device.
A remote attacker could use this issue to cause guest network consumption,
resulting in a denial of service. (CVE-2015-7295)
Qinghao Tang and Ling Liu discovered that QEMU incorrectly handled the
pcnet driver when used in loopback mode. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-7504)
Ling Liu and Jason Wang discovered that QEMU incorrectly handled the
pcnet driver. A remote attacker could use
Red Hat
Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
vendor_redhat·2015-11-30·CVSS 8.8
CVE-2015-7504 [HIGH] CWE-122 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
A heap-based buffer overflow flaw was discovered in the way QEMU's AMD PC-Net II Ethernet Controller emulation
received certain packets in loopback mode. A privileged user (with the CAP_SYS_RAWIO capability) inside a guest could use this flaw to crash the host QEMU process (resulting in denial of service) or, potentially, execute arbitrary code with privileges of the host QEMU process.
Statement: This issue does not affect the versions of the qemu-kvm packages as shipped with Red Hat Enterpri
Debian
CVE-2015-7504: qemu - Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QE...
vendor_debian·2015·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504: qemu - Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QE...
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.5+dfsg-1)
forky: resolved (fixed in 1:2.5+dfsg-1)
sid: resolved (fixed in 1:2.5+dfsg-1)
trixie: resolved (fixed in 1:2.5+dfsg-1)
GHSA
GHSA-55jf-8f2x-33wf: Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet
ghsa_unreviewed·2022-05-13
CVE-2015-7504 [HIGH] CWE-787 GHSA-55jf-8f2x-33wf: Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
OSV
CVE-2015-7504: Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet
osv·2017-10-16·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504: Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-12-03·CVSS 5.0
CVE-2015-7295 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Jason Wang discovered that QEMU incorrectly handled the virtio-net device.
A remote attacker could use this issue to cause guest network consumption,
resulting in a denial of service. (CVE-2015-7295)
Qinghao Tang and Ling Liu discovered that QEMU incorrectly handled the
pcnet driver when used in loopback mode. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-7504)
Ling Liu and Jason Wang discovered that QEMU incorrectly handled the
pcnet driver. A remote attacker could use this issue to cause a denial of
service, or possibl
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
bugzilla·2015-11-30·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2015-7504 xen: Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
bugzilla·2015-11-30·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504 xen: Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
CVE-2015-7504 xen: Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-7]
bugzilla·2015-11-30·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-7]
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for qemu: see blocks bu
Bugzilla
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-5]
bugzilla·2015-11-30·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-5]
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for qemu: see blocks bu
Bugzilla
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
bugzilla·2015-09-09·CVSS 8.8
CVE-2015-7504 [HIGH] CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
CVE-2015-7504 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive
Qemu emulator built with the AMD PC-Net II Ethernet Controller support is vulnerable to a heap buffer overflow flaw. While receiving packets in the loopback mode, it appends CRC code to the receive buffer. If the data size
given is same as the receive buffer size, the appended CRC code overwrites 4 bytes beyond this 's->buffer' array.
A privileged(CAP_SYS_RAWIO) user inside guest could use this flaw to crash
the Qemu instance resulting in DoS or potentially execute arbitrary code
with privileges of the Qemu process on the host.
Upstream fix:
-> http://git.qemu.org/?p=qemu.git;a=commit;h=837f21aacf5a714c23ddaadbbc5212f9
Reference:
-> http://www.openwall.com/lists/oss-security/2015/11/30/2
-> http://www.openwall
http://rhn.redhat.com/errata/RHSA-2015-2694.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2695.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2696.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2015/11/30/2http://www.securityfocus.com/bid/78227http://www.securitytracker.com/id/1034268http://xenbits.xen.org/xsa/advisory-162.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2015-11/msg06342.htmlhttps://security.gentoo.org/glsa/201602-01https://security.gentoo.org/glsa/201604-03http://rhn.redhat.com/errata/RHSA-2015-2694.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2695.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2696.htmlhttp://www.debian.org/security/2016/dsa-3469http://www.debian.org/security/2016/dsa-3470http://www.debian.org/security/2016/dsa-3471http://www.openwall.com/lists/oss-security/2015/11/30/2http://www.securityfocus.com/bid/78227http://www.securitytracker.com/id/1034268http://xenbits.xen.org/xsa/advisory-162.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2015-11/msg06342.htmlhttps://security.gentoo.org/glsa/201602-01https://security.gentoo.org/glsa/201604-03
2017-10-16
Published