cbcvebase.
CVE-2015-7512
published 2016-01-08

CVE-2015-7512: Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of…

PriorityP355critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
7.73%
94.0th percentile
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.5+dfsg-1 (bookworm)qemu 1:2.5+dfsg-1 (bookworm)
oraclelinux
qemuqemu<= 2.4.1
qemuqemu
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.212.0.0+dfsg-2ubuntu1.21
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatopenstack
redhatvirtualization

Detection & IOCsextracted from sources · hover to see the quote

pathhw/net/pcnet.c
  • The vulnerability is in the pcnet_receive function in hw/net/pcnet.c; monitor for QEMU processes handling AMD PC-Net II (pcnet) NIC emulation in non-loopback mode receiving oversized packets that exceed the guest NIC MTU.
  • Exploitation requires the guest NIC to be configured with a larger-than-normal MTU limit; alert on QEMU guest configurations where the pcnet adapter MTU is set above standard (1500 bytes).
  • The pcnet backend driver must be explicitly enabled per-guest; flag any QEMU/KVM guest configurations that explicitly enable the AMD PCNet adapter (e.g., -net nic,model=pcnet), as it is not enabled by default.
  • ·QEMU on RHEL 7 and RHEV 3 (RHEL 7 base) are NOT affected because the pcnet backend driver is not enabled in those builds.
  • ·Exploitation is only possible in non-loopback mode when a remote attacker sends a large packet to a guest with a larger-than-default MTU; loopback-mode exploitation is a separate issue (CVE-2015-7504).
  • ·When QEMU is used with libvirt, exploitation impact is reduced because attackers would be isolated by the libvirt AppArmor profile.

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.0CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.