Wind River Support Network


LIN8-2802 : Security Advisory - qemu - CVE-2015-7504

Created: Feb 18, 2016    Updated: Dec 3, 2018
Resolved Date: Feb 29, 2016
Found In Version: 8.0
Fix Version:
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace


A heap-based buffer overflow flaw was discovered in the way QEMU's AMD PC-Net II Ethernet Controller emulation received certain packets in loopback mode. A privileged user (with the CAP_SYS_RAWIO capability) inside a guest could use this flaw to crash the host QEMU process (resulting in denial of service) or, potentially, execute arbitrary code with privileges of the host QEMU process.

Other Downloads


Live chat