qemu: pcnet: multi-tmd buffer overflow in the tx path
Published Jun 15, 2015
7.5
HIGHCVSS 2.0
EPSS 9.68%
Description
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
Affected products
No data.
Configuration 2
- ≤ 15.1
Configuration 3
- 12.04
- 14.04
- 14.10
- 15.04
Configuration 4
- 7.0
- 8.0
Configuration 5
- 6.0
- 6.6
- 5.0
- 6.0
- 6.6
- 6.6
- 5.0
- 6.0
Configuration 6
- 5.0
- 3.0
Running on/with
- 6.0
Configuration 7
- 20
- 21
- 22
Configuration 8
- 11
- 11
- 12
- 10
- 11
- 11
- 11
- 12
- 11
- 12
No data.
RHEV 3.X Hypervisor and Agents for RHEL-6
qemu-kvm-rhev-2:0.12.1.2-2.448.el6_6.4
Fixed · RHSA-2015:1088
Red Hat Enterprise Linux 5
kvm-0:83-273.el5_11
Fixed · RHSA-2015:1189
Red Hat Enterprise Linux 6
qemu-kvm-2:0.12.1.2-2.448.el6_6.4
Fixed · RHSA-2015:1087
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.448.el6_6.4
Fixed · RHSA-2015:1089
Red Hat Enterprise Linux 5
kvm
Affected
Red Hat Enterprise Linux 5
xen
Will not fix
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-rhev
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
qemu-kvm-rhev
Not affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 4
qemu-kvm-rhev
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV 3.X Hypervisor and Agents for RHEL-6 | qemu-kvm-rhev-2:0.12.1.2-2.448.el6_6.4 | Fixed | RHSA-2015:1088 |
| Red Hat Enterprise Linux 5 | kvm-0:83-273.el5_11 | Fixed | RHSA-2015:1189 |
| Red Hat Enterprise Linux 6 | qemu-kvm-2:0.12.1.2-2.448.el6_6.4 | Fixed | RHSA-2015:1087 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.448.el6_6.4 | Fixed | RHSA-2015:1089 |
| Red Hat Enterprise Linux 5 | kvm | Affected | n/a |
| Red Hat Enterprise Linux 5 | xen | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 4 | qemu-kvm-rhev | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 7 as they do not enable the pcnet backend driver. This issue does not affect the Red Hat Enterprise Linux 7 based versions of the qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. This issue affects the versions of the kvm and xen packages as shipped with Red Hat Enterprise Linux 5, the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6, and the Red Hat Enterprise Linux 6 based versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. Future updates for the respective releases may address this flaw. Please note that AMD PCNet adapter has to be explicitly enabled per-guest as it is not enabled in default configuration and is not supported by Red Hat in Red Hat Enterprise Linux 6 (for a list of supported devices please consult https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Virtualization_Administration_Guide/sect-whitelist-device-options.html).
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.68% (0.09679) | 95.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.67% (0.09668) | 94.86th | v5 (v2026.06.15) |
| Jun 7, 2026 | 14.90% (0.14897) | 94.67th | v4 (v2025.03.14) |
| May 13, 2026 | 18.02% (0.18024) | 95.23th | v4 (v2025.03.14) |
| Dec 28, 2025 | 20.57% (0.20573) | 95.38th | v4 (v2025.03.14) |
| Dec 27, 2025 | 18.02% (0.18024) | 94.97th | v4 (v2025.03.14) |
| Dec 16, 2025 | 20.57% (0.20573) | 95.38th | v4 (v2025.03.14) |
| Dec 1, 2025 | 17.52% (0.17515) | 94.86th | v4 (v2025.03.14) |
| May 21, 2025 | 4.54% (0.04545) | 88.59th | v4 (v2025.03.14) |
| Apr 5, 2025 | 15.25% (0.15255) | 94.05th | v4 (v2025.03.14) |
| Mar 30, 2025 | 26.02% (0.26016) | 95.83th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.03% (0.17031) | 91.70th | v4 (v2025.03.14) |
| Mar 21, 2025 | 26.02% (0.26016) | 95.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 21.50% (0.21501) | 95.25th | v4 (v2025.03.14) |
| Dec 17, 2024 | 11.92% (0.11919) | 95.31th | v3 (v2023.03.01) |
| Aug 29, 2024 | 7.28% (0.07279) | 94.17th | v3 (v2023.03.01) |
| May 22, 2024 | 5.27% (0.05274) | 93.04th | v3 (v2023.03.01) |
| Feb 20, 2024 | 6.85% (0.06848) | 93.66th | v3 (v2023.03.01) |
| Mar 7, 2023 | 5.14% (0.05136) | 91.70th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.25% (0.12248) | 95.30th | v2 (v2022.01.01) |
| Feb 13, 2023 | 12.25% (0.12248) | 95.13th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.42% (0.04421) | 87.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.25% (0.12248) | 94.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.25% (0.12248) | 89.34th | v2 (v2022.01.01) |
References (32)
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698 x_refsource_CONFIRMThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160669.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160677.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1087.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1088.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1089.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1189.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2015/dsa-3284 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2015/dsa-3285 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2015/dsa-3286 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/75123 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032545 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2630-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-135.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-3209 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1225882 Issue Tracking
- https://kb.juniper.net/JSA10783 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-3209
- https://security.gentoo.org/glsa/201510-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.gentoo.org/glsa/201604-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2015-3209
Change history (0)
No recorded changes yet.