Wind River Support Network


LIN7-5666 : Security Advisory - qemu - CVE-2015-7504

Created: Feb 18, 2016    Updated: Sep 8, 2018
Resolved Date: Mar 1, 2016
Found In Version: 7.0
Fix Version:
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace


A heap-based buffer overflow flaw was discovered in the way QEMU's AMD PC-Net II Ethernet Controller emulation received certain packets in loopback mode. A privileged user (with the CAP_SYS_RAWIO capability) inside a guest could use this flaw to crash the host QEMU process (resulting in denial of service) or, potentially, execute arbitrary code with privileges of the host QEMU process.

Other Downloads


Live chat