CVE-2015-3215
high
CVSS v3
7.5
VIR risk
7.5
Description
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | virtio-win | - | |
References
- http://rhn.redhat.com/errata/RHSA-2015-1043.html
- http://rhn.redhat.com/errata/RHSA-2015-1044.html
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/723416fa4210b7464b28eab89cc76252e6193ac1
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/fbfa4d1083ea84c5429992ca3e996d7d4fbc8238
- https://www.redhat.com/security/data/cve/CVE-2015-3215.html
- http://rhn.redhat.com/errata/RHSA-2015-1043.html
- http://rhn.redhat.com/errata/RHSA-2015-1044.html
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/723416fa4210b7464b28eab89cc76252e6193ac1
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/fbfa4d1083ea84c5429992ca3e996d7d4fbc8238
- https://www.redhat.com/security/data/cve/CVE-2015-3215.html
CWEs
CWE-20
💬 Discuss CVE-2015-3215 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.