cbcvebase.
CVE-2015-7512
published 2016-01-08

CVE-2015-7512: Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of…

critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.5+dfsg-1 (bookworm)qemu 1:2.5+dfsg-1 (bookworm)
oraclelinux
qemuqemu<= 2.4.1
qemuqemu
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-11:2.5+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.212.0.0+dfsg-2ubuntu1.21
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatopenstack
redhatvirtualization

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
osv9.0CRITICAL