CVE Vulnerabilities

CVE-2015-5166

Published: Aug 12, 2015 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
2.9 MODERATE
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 21 (including) 21 (including)
Fedora Fedoraproject 22 (including) 22 (including)
Qemu Ubuntu devel *
Qemu Ubuntu utopic *
Qemu Ubuntu vivid *
Xen Ubuntu utopic *

References