CVE Vulnerabilities

CVE-2015-5165

Use of Uninitialized Resource

Published: Aug 12, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Xen Xen * 4.5.0 (including)
Xen Xen 4.5.1 (including) 4.5.1 (including)

Potential Mitigations

References