CVE-2015-3214
Published: 17 June 2015
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Notes
Author | Note |
---|---|
sbeattie | introduced in 0505bcdec8228d8de39ab1a02644e71999e7c05, 1.3.0 first version |
Priority
Status
Package | Release | Status |
---|---|---|
qemu Launchpad, Ubuntu, Debian |
precise |
Does not exist
|
trusty |
Released
(2.0.0+dfsg-2ubuntu1.15)
|
|
upstream |
Needs triage
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Released
(1:2.2+dfsg-5expubuntu9.3)
|
|
Patches: upstream: http://git.qemu.org/?p=qemu.git;a=commitdiff;h=d4862a87e31a51de9eb260f25c9e99a75efe3235 |
||
qemu-kvm Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
(pre 1.3.0)
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|