CVE-2015-4106
03.06.2015, 20:59
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 𝑥 ≤ 2.3.1 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| citrix | xenserver | 6.0 |
| citrix | xenserver | 6.0.2 |
| citrix | xenserver | 6.1.0 |
| citrix | xenserver | 6.2.0 |
| citrix | xenserver | 6.5 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| canonical | ubuntu_linux | 15.04 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||||||
| xen |
|
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||
| qemu-kvm |
| ||||||||
| xen |
|
References