CVE Vulnerabilities

CVE-2015-6815

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 31, 2020 | Modified: Nov 21, 2024
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
2.7 LOW
AV:A/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 2.4.0.1 (excluding)
Qemu Ubuntu devel *
Qemu Ubuntu trusty *
Qemu Ubuntu vivid *
Qemu-kvm Ubuntu precise *

References