CVE-2015-8818Out-of-bounds Write in Qemu

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 73.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 29
Latest updateMay 13

Description

The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/qemu< qemu 1:2.4+dfsg-1a (bookworm)
Debianqemu/qemu< 1:2.4+dfsg-1a+3
NVDqemu/qemu2.3.1

🔴Vulnerability Details

2
GHSA
GHSA-v5jw-2c5m-f8hv: The cpu_physical_memory_write_rom_internal function in exec2022-05-13
OSV
CVE-2015-8818: The cpu_physical_memory_write_rom_internal function in exec2016-12-29

📋Vendor Advisories

2
Red Hat
Qemu: OOB access in address_space_rw leads to segmentation fault2016-01-27
Debian
CVE-2015-8818: qemu - The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick...2015

💬Community

1
Bugzilla
CVE-2015-8817 CVE-2015-8818 Qemu: OOB access in address_space_rw leads to segmentation fault2016-01-21