A heap-based buffer overflow issue was found in the QEMU emulator's VNC display driver. It could occur while refreshing the VNC server's display surface using the vnc_refresh_server_surface() routine. A privileged guest user could use this flaw to corrupt the heap memory and crash the QEMU process instance, or to potentially use it to execute arbitrary code on the host.
Find out more about CVE-2015-5225 from the MITRE CVE dictionary dictionary and NIST NVD.
This issue does not affect the versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue does not affect the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7.
This issue does not affect the Red Hat Enterprise Linux 6 based versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3.
This issue does affect the Red Hat Enterprise Linux 7 based versions of the qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. Future updates for this release may address this flaw.
Base Score | 6.5 |
---|---|
Base Metrics | AV:A/AC:H/Au:S/C:C/I:C/A:C |
Access Vector | Adjacent Network |
Access Complexity | High |
Authentication | Single |
Confidentiality Impact | Complete |
Integrity Impact | Complete |
Availability Impact | Complete |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 (qemu-kvm-rhev) | RHSA-2015:1772 | 2015-09-14 |
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (qemu-kvm-rhev) | RHSA-2015:1837 | 2015-09-24 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (qemu-kvm-rhev) | RHSA-2015:1772 | 2015-09-14 |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 (qemu-kvm-rhev) | RHSA-2015:1772 | 2015-09-14 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 7 | qemu-kvm | Not affected |
Red Hat Enterprise Linux 6 | qemu-kvm | Not affected |
Red Hat Enterprise Linux 5 | xen | Not affected |
Red Hat Enterprise Linux 5 | kvm | Not affected |