4.9
CVSSv2

CVE-2015-2756

Published: 01/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

QEMU, as used in Xen 3.3.x up to and including 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 7.0

xen xen 4.4.0

xen xen 4.3.0

xen xen 4.5.0

xen xen 4.3.1

xen xen 4.3.2

xen xen 4.4.1

fedoraproject fedora 21

fedoraproject fedora 20

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 15.04

canonical ubuntu linux 14.10

Vendor Advisories

Several security issues were fixed in QEMU ...
Debian Bug report logs - #781620 CVE-2015-2751 CVE-2015-2752 CVE-2015-2756 Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 31 Mar 2015 17:15:02 UTC Severity: important Tags: fixed-upstream, security, upstr ...
Debian Bug report logs - #781620 CVE-2015-2751 CVE-2015-2752 CVE-2015-2756 Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 31 Mar 2015 17:15:02 UTC Severity: important Tags: fixed-upstream, security, upstr ...
Debian Bug report logs - #781250 qemu: CVE-2014-9718 CVE-2015-1779 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 26 Mar 2015 13:48:13 UTC Severity: important Tags: confirmed, security, upstream Fixe ...
Several vulnerabilities were discovered in the qemu virtualisation solution: CVE-2014-9718 It was discovered that the IDE controller emulation is susceptible to denial of service CVE-2015-1779 Daniel P Berrange discovered a denial of service vulnerability in the VNC web socket decoder CVE-2015-2756 Jan Beulich discovered tha ...
QEMU, as used in Xen 33x through 45x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Reque ...