CVE-2015-8554

Publication date 14 April 2016

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."

Status

Package Ubuntu Release Status
qemu 15.10 wily
Not affected
15.04 vivid
Not affected
14.04 LTS trusty
Not affected
12.04 LTS precise Not in release
qemu-kvm 15.10 wily Not in release
15.04 vivid Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
xen 15.10 wily
Not affected
15.04 vivid
Not affected
14.04 LTS trusty
Fixed 4.4.2-0ubuntu0.14.04.4
12.04 LTS precise
Fixed 4.1.6.1-0ubuntu0.12.04.8

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities