CVE-2015-3456
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
- Affected products
- Alt Linux, Arista Eos, Centos, Check Point Gaia, Kvm, Qemu, Red Hat, Suse
- Qemu
- ≤ 2.3.0
- Fix
- Available
- CVSS 2.0
- 7.7 HIGH
- EPSS
- 15.3% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2015-05-13
CVE-2015-3456 at NVD
5 known exploits for CVE-2015-3456
Proof-of-concept code and exploit modules indexed by Sploitus