MEDIUM · 6.9

CVE-2015-3214

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrar...

Vulnerability Description

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
QemuQemu<= 2.3.0
LinuxLinux Kernel<= 2.6.32
AristaEos4.12
DebianDebian Linux7.0
LenovoEmc Px12-400R Ivx< 1.0.10.33264
LenovoEmc Px12-450R Ivx< 1.0.10.33264
RedhatOpenstack5.0
RedhatVirtualization3.0
RedhatEnterprise Linux Compute Node Eus7.1
RedhatEnterprise Linux For Power Big Endian7.0
RedhatEnterprise Linux For Power Big Endian Eus7.1_ppc64
RedhatEnterprise Linux For Scientific Computing7.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Server Eus7.1
RedhatEnterprise Linux Server From Rhui7.0
RedhatEnterprise Linux Server Tus7.3
RedhatEnterprise Linux Server Update Services For Sap Solutions7.2
RedhatEnterprise Linux Workstation7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3214?

CVE-2015-3214 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrar...

How severe is CVE-2015-3214?

CVE-2015-3214 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3214?

Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Linux Linux Kernel, Arista Eos, Debian Debian Linux, Lenovo Emc Px12-400R Ivx.