CVE-2015-3214
Description
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.593
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in QEMU 2.3.0 | Windows |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-block-curl-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-block-curl-debuginfo-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Server 12 ) qemu-block-rbd-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Server 12 ) qemu-block-rbd-debuginfo-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-debugsource-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Server 12 ) qemu-guest-agent-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Server 12 ) qemu-guest-agent-debuginfo-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-ipxe-1.0.0-48.19.1.noarch.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-kvm-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Server 12 ) qemu-lang-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-seabios-1.7.4-48.19.1.noarch.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-sgabios-8-48.19.1.noarch.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-tools-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-tools-debuginfo-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-vgabios-1.7.4-48.19.1.noarch.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-x86-2.0.2-48.19.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1560-1(SUSE Linux Enterprise Desktop 12 ) qemu-x86-debuginfo-2.0.2-48.19.1.x86_64.rpm | Linux |
| Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-3214) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234