VDB

DEBIAN-CVE-2015-3214

DEBIAN-CVE-2015-3214 PUBLISHED CVSS 9.300000190734863 CRITICAL

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:13xen0, 0, 0
Debian:11qemu0, 0, 0
Debian:13qemu0, 0, 0
Debian:14qemu0, 0, 0
Debian:12qemu0, 0, 0
Debian:11xen0, 0, 0
Debian:12xen0, 0, 0
Debian:14xen0, 0, 0

Timeline

  • Aug 31, 2015 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›