CVE-2015-7512
9.0
CRITICAL · CVSS 3.1 · EPSS 7.7% (pctl 94)
In your normal cycle
Critical by CVSS (9), but no sign of active exploitation.
Description
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 7.73% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-01-08 |
| Last modified | 2026-06-17 |
Affected (9)
| Vendor | Product |
|---|---|
| debian | debian linux |
| oracle | linux |
| qemu | qemu |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| redhat | openstack |
| redhat | virtualization |
References
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=8b98a2f07175d46c3f7217639bd5e03f
- http://rhn.redhat.com/errata/RHSA-2015-2694.html
- http://rhn.redhat.com/errata/RHSA-2015-2695.html
- http://rhn.redhat.com/errata/RHSA-2015-2696.html
- http://www.debian.org/security/2016/dsa-3469
- http://www.debian.org/security/2016/dsa-3470
- http://www.debian.org/security/2016/dsa-3471
- http://www.openwall.com/lists/oss-security/2015/11/30/3
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/78230
- http://www.securitytracker.com/id/1034527
- https://security.gentoo.org/glsa/201602-01
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=8b98a2f07175d46c3f7217639bd5e03f
- http://rhn.redhat.com/errata/RHSA-2015-2694.html
- http://rhn.redhat.com/errata/RHSA-2015-2695.html
- http://rhn.redhat.com/errata/RHSA-2015-2696.html
- http://www.debian.org/security/2016/dsa-3469
- http://www.debian.org/security/2016/dsa-3470
- http://www.debian.org/security/2016/dsa-3471
- http://www.openwall.com/lists/oss-security/2015/11/30/3
→ the Explorer · watch your stack · NVD