CVE Vulnerabilities

CVE-2015-5278

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 23, 2020 | Modified: Nov 30, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:A/AC:H/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
LOW

The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 2.4.0.1 (excluding)
Qemu Ubuntu devel *
Qemu Ubuntu trusty *
Qemu Ubuntu upstream *
Qemu Ubuntu vivid *
Qemu-kvm Ubuntu precise *
Qemu-kvm Ubuntu upstream *

References