Description
Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5173 | Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice. |
Ubuntu USN |
USN-2724-1 | QEMU vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:07.558Z
Reserved: 2015-07-01T00:00:00.000Z
Link: CVE-2015-5166
No data.
Status : Modified
Published: 2015-08-12T14:59:25.247
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-5166
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN