CVE Vulnerabilities

CVE-2015-5165

Use of Uninitialized Resource

Published: Aug 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
XenXen*4.5.0 (including)
XenXen4.5.1 (including)4.5.1 (including)
Red Hat Enterprise Linux 6RedHatqemu-kvm-2:0.12.1.2-2.479.el6_7.1*
Red Hat Enterprise Linux 7RedHatqemu-kvm-10:1.5.3-86.el7_1.6*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatqemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.1*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatqemu-kvm-rhev-10:2.1.2-23.el7_1.8*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatqemu-kvm-rhev-10:2.1.2-23.el7_1.8*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatqemu-kvm-rhev-10:2.1.2-23.el7_1.8*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatqemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.1*
RHEV 3.X Hypervisor and Agents for RHEL-7RedHatqemu-kvm-rhev-10:2.1.2-23.el7_1.8*
QemuUbuntudevel*
QemuUbuntuesm-infra-legacy/trusty*
QemuUbuntutrusty*
QemuUbuntutrusty/esm*
QemuUbuntuutopic*
QemuUbuntuvivid*
Qemu-kvmUbuntuprecise*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuutopic*

Potential Mitigations

References