3.3
CVSSv2

CVE-2015-8666

Published: 11/04/2017 Updated: 12/02/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.9 | Impact Score: 5.8 | Exploitability Score: 1.5
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

qemu qemu 2.5.0

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in QEMU ...
A heap-based buffer overflow flaw was discovered in the QEMU emulator built with the Q35-chipset-based PC system emulator During VM-guest migration, more data (8 bytes) is moved than the allocated memory area A privileged guest user could use this flaw to corrupt the VM guest image, which could potentially lead to a denial of service ...