Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-8744
Description:QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
Test IDs: 1.3.6.1.4.1.25623.1.0.703471  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-8744
1034576
http://www.securitytracker.com/id/1034576
79821
http://www.securityfocus.com/bid/79821
DSA-3471
http://www.debian.org/security/2016/dsa-3471
GLSA-201602-01
https://security.gentoo.org/glsa/201602-01
[oss-security] 20160104 CVE request Qemu: net: vmxnet3: incorrect l2 header validation leads to a crash
http://www.openwall.com/lists/oss-security/2016/01/04/3
[oss-security] 20160104 Re: CVE request Qemu: net: vmxnet3: incorrect l2 header validation leads to a crash
http://www.openwall.com/lists/oss-security/2016/01/04/6
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=a7278b36fcab9af469563bd7b
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=a7278b36fcab9af469563bd7b
https://bugzilla.redhat.com/show_bug.cgi?id=1270871
https://bugzilla.redhat.com/show_bug.cgi?id=1270871




© 1998-2025 E-Soft Inc. All rights reserved.