PublicDateAtUSN: 2015-08-12
Candidate: CVE-2015-5165
PublicDate: 2015-08-12 14:59:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5165
 http://xenbits.xen.org/xsa/advisory-140.html
 https://ubuntu.com/security/notices/USN-2724-1
Description:
 The C+ mode offload emulation in the RTL8139 network card device model in
 QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read
 process heap memory via unspecified vectors.
Ubuntu-Description:
Notes:
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794610
Priority: medium
Discovered-by: Donghai Zhu
Assigned-to: mdeslaur
CVSS: 

Tags_xen: universe-binary
Patches_xen:
upstream_xen: needs-triage
precise_xen: released (4.1.6.1-0ubuntu0.12.04.6)
trusty_xen: released (4.4.2-0ubuntu0.14.04.2)
trusty/esm_xen: DNE (trusty was released [4.4.2-0ubuntu0.14.04.2])
utopic_xen: ignored (reached end-of-life)
vivid_xen: not-affected (code not present)
devel_xen: not-affected (code not present)

Patches_qemu-kvm:
upstream_qemu-kvm: needs-triage
precise_qemu-kvm: released (1.0+noroms-0ubuntu14.24)
trusty_qemu-kvm: DNE
trusty/esm_qemu-kvm: DNE
utopic_qemu-kvm: DNE
vivid_qemu-kvm: DNE
devel_qemu-kvm: DNE

Patches_qemu:
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=39b8e7dcaf04cbdb926b478f825b160d852752b5
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=d6812d60e7932de3cd0f602c0ee63dd3d09f1847
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=e1c120a9c54872f8a538ff9129d928de4e865cbd
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=03247d43c577dfea8181cd40177ad5ba77c8db76
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=c6296ea88df040054ccd781f3945fe103f8c7c17
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=4240be45632db7831129f124bcf53c1223825b0f
 upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=8357946b15f0a31f73dd691b7da95f29318ed310
upstream_qemu: needs-triage
precise_qemu: DNE
trusty_qemu: released (2.0.0+dfsg-2ubuntu1.17)
trusty/esm_qemu: released (2.0.0+dfsg-2ubuntu1.17)
utopic_qemu: ignored (reached end-of-life)
vivid_qemu: released (1:2.2+dfsg-5expubuntu9.4)
devel_qemu: released (1:2.3+dfsg-5ubuntu4)
