Bugzilla – Bug 944697
VUL-1: CVE-2015-6815: qemu: net: e1000: infinite loop issue
Last modified: 2021-01-22 08:57:20 UTC
rh#1260076 Qemu emulator built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing transmit descriptor data when sending a network packet. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS. Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg01199.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1260076 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6815 http://seclists.org/oss-sec/2015/q3/501
bugbot adjusting priority
Upstream commit: http://git.qemu.org/?p=qemu.git;a=commit;h=b947ac2bf26479e710489739c465c8af336599e7
This is an autogenerated message for OBS integration: This bug (944697) was mentioned in https://build.opensuse.org/request/show/337319 Leap:42.1 / qemu
SUSE-SU-2015:1853-1: An update that solves 8 vulnerabilities and has 6 fixes is now available. Category: security (important) Bug References: 877642,907514,910258,918984,923967,932267,941074,944463,944697,947165,950367,950703,950705,950706 CVE References: CVE-2014-0222,CVE-2015-4037,CVE-2015-5239,CVE-2015-6815,CVE-2015-7311,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP3 (src): xen-4.2.5_14-18.2 SUSE Linux Enterprise Server 11-SP3 (src): xen-4.2.5_14-18.2 SUSE Linux Enterprise Desktop 11-SP3 (src): xen-4.2.5_14-18.2 SUSE Linux Enterprise Debuginfo 11-SP3 (src): xen-4.2.5_14-18.2
SUSE-SU-2015:1894-1: An update that solves 8 vulnerabilities and has 9 fixes is now available. Category: security (important) Bug References: 877642,901488,907514,910258,918984,923967,932267,944463,944697,945167,947165,949138,949549,950367,950703,950705,950706 CVE References: CVE-2014-0222,CVE-2015-4037,CVE-2015-5239,CVE-2015-6815,CVE-2015-7311,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): xen-4.4.3_02-26.2 SUSE Linux Enterprise Server 11-SP4 (src): xen-4.4.3_02-26.2 SUSE Linux Enterprise Desktop 11-SP4 (src): xen-4.4.3_02-26.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): xen-4.4.3_02-26.2
SUSE-SU-2015:1908-1: An update that solves 8 vulnerabilities and has 8 fixes is now available. Category: security (important) Bug References: 877642,901488,907514,910258,918984,923967,932267,944463,944697,945167,947165,949138,950367,950703,950705,950706 CVE References: CVE-2014-0222,CVE-2015-4037,CVE-2015-5239,CVE-2015-6815,CVE-2015-7311,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): xen-4.4.3_02-22.12.1 SUSE Linux Enterprise Server 12 (src): xen-4.4.3_02-22.12.1 SUSE Linux Enterprise Desktop 12 (src): xen-4.4.3_02-22.12.1
no reproducer available for qemu
SUSE-SU-2015:1952-1: An update that solves 7 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 877642,932267,944463,944697,950367,950703,950705,950706 CVE References: CVE-2014-0222,CVE-2015-4037,CVE-2015-5239,CVE-2015-6815,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971 Sources used: SUSE Linux Enterprise Server 11-SP2-LTSS (src): xen-4.1.6_08-20.1 SUSE Linux Enterprise Debuginfo 11-SP2 (src): xen-4.1.6_08-20.1
openSUSE-SU-2015:1964-1: An update that solves 12 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 877642,932267,938344,939709,939712,941074,944463,944697,947165,950367,950703,950705,950706,951845 CVE References: CVE-2014-0222,CVE-2015-4037,CVE-2015-5154,CVE-2015-5165,CVE-2015-5166,CVE-2015-5239,CVE-2015-6815,CVE-2015-7311,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971,CVE-2015-7972 Sources used: openSUSE 13.1 (src): xen-4.3.4_06-50.1
openSUSE-SU-2015:2003-1: An update that solves 13 vulnerabilities and has 9 fixes is now available. Category: security (important) Bug References: 877642,901488,907514,910258,918984,923967,925466,932267,935634,938344,939709,939712,944463,944697,945167,947165,949138,950367,950703,950705,950706,951845 CVE References: CVE-2014-0222,CVE-2015-3259,CVE-2015-4037,CVE-2015-5154,CVE-2015-5165,CVE-2015-5166,CVE-2015-5239,CVE-2015-6815,CVE-2015-7311,CVE-2015-7835,CVE-2015-7969,CVE-2015-7971,CVE-2015-7972 Sources used: openSUSE 13.2 (src): xen-4.4.3_02-30.1
openSUSE-SU-2016:0995-1: An update that fixes 33 vulnerabilities is now available. Category: security (important) Bug References: 944463,944697,945989,956829,960334,960707,960725,960835,960861,960862,961332,961358,961691,962335,962360,962611,962627,962632,962642,962758,963782,964413,964431,964452,964644,964925,964929,964950,965156,965315,965317,967012,967969 CVE References: CVE-2013-4529,CVE-2013-4530,CVE-2013-4533,CVE-2013-4534,CVE-2013-4537,CVE-2013-4538,CVE-2013-4539,CVE-2014-0222,CVE-2014-3689,CVE-2014-7815,CVE-2014-9718,CVE-2015-1779,CVE-2015-5239,CVE-2015-5278,CVE-2015-6815,CVE-2015-6855,CVE-2015-7512,CVE-2015-8345,CVE-2015-8613,CVE-2015-8619,CVE-2015-8743,CVE-2015-8744,CVE-2015-8745,CVE-2016-1568,CVE-2016-1570,CVE-2016-1571,CVE-2016-1714,CVE-2016-1981,CVE-2016-2198,CVE-2016-2270,CVE-2016-2271,CVE-2016-2392,CVE-2016-2538 Sources used: openSUSE 13.2 (src): xen-4.4.4_02-43.1
SUSE-SU-2016:2628-1: An update that fixes 16 vulnerabilities is now available. Category: security (moderate) Bug References: 902737,944697,967012,967013,982017,982018,982019,982222,982223,982285,982959,983961,983982,991080,991466,996441 CVE References: CVE-2014-7815,CVE-2015-6815,CVE-2016-2391,CVE-2016-2392,CVE-2016-4453,CVE-2016-4454,CVE-2016-5105,CVE-2016-5106,CVE-2016-5107,CVE-2016-5126,CVE-2016-5238,CVE-2016-5337,CVE-2016-5338,CVE-2016-5403,CVE-2016-6490,CVE-2016-7116 Sources used: SUSE Linux Enterprise Server 11-SP4 (src): kvm-1.4.2-47.1
SUSE-SU-2016:2781-1: An update that fixes 21 vulnerabilities is now available. Category: security (moderate) Bug References: 893323,944697,967012,967013,982017,982018,982019,982222,982223,982285,982959,983961,983982,991080,991466,994760,994771,994774,996441,997858,997859 CVE References: CVE-2014-5388,CVE-2015-6815,CVE-2016-2391,CVE-2016-2392,CVE-2016-4453,CVE-2016-4454,CVE-2016-5105,CVE-2016-5106,CVE-2016-5107,CVE-2016-5126,CVE-2016-5238,CVE-2016-5337,CVE-2016-5338,CVE-2016-5403,CVE-2016-6490,CVE-2016-6833,CVE-2016-6836,CVE-2016-6888,CVE-2016-7116,CVE-2016-7155,CVE-2016-7156 Sources used: SUSE Linux Enterprise Server for SAP 12 (src): qemu-2.0.2-48.22.1 SUSE Linux Enterprise Server 12-LTSS (src): qemu-2.0.2-48.22.1
fixed