CVE Vulnerabilities

CVE-2015-5165

Use of Uninitialized Resource

Published: Aug 12, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Xen Xen * 4.5.0 (including)
Xen Xen 4.5.1 (including) 4.5.1 (including)
Red Hat Enterprise Linux 6 RedHat qemu-kvm-2:0.12.1.2-2.479.el6_7.1 *
Red Hat Enterprise Linux 7 RedHat qemu-kvm-10:1.5.3-86.el7_1.6 *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.1 *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat qemu-kvm-rhev-10:2.1.2-23.el7_1.8 *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat qemu-kvm-rhev-10:2.1.2-23.el7_1.8 *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat qemu-kvm-rhev-10:2.1.2-23.el7_1.8 *
RHEV 3.X Hypervisor and Agents for RHEL-6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.479.el6_7.1 *
RHEV 3.X Hypervisor and Agents for RHEL-7 RedHat qemu-kvm-rhev-10:2.1.2-23.el7_1.8 *
Qemu Ubuntu devel *
Qemu Ubuntu trusty *
Qemu Ubuntu utopic *
Qemu Ubuntu vivid *
Qemu-kvm Ubuntu precise *
Xen Ubuntu precise *
Xen Ubuntu trusty *
Xen Ubuntu utopic *

Potential Mitigations

References