Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora | Fedoraproject | 21 (including) | 21 (including) |
Fedora | Fedoraproject | 22 (including) | 22 (including) |
Qemu | Ubuntu | devel | * |
Qemu | Ubuntu | utopic | * |
Qemu | Ubuntu | vivid | * |
Xen | Ubuntu | utopic | * |