CVE-2015-7513

medium
Published 2016-02-08 · Modified 2026-05-06
CVSS v3
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
VIR risk
6.5

Description

arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.

Predictions

Exploit likelihood
65%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.3.3-3
debian debianbullseyefixed4.3.3-3
debian debianforkyfixed4.3.3-3
debian debiansidfixed4.3.3-3
debian debiantrixiefixed4.3.3-3
debian debian7.0affected
debian debian8.0affected
fedora fedora22affected
fedora fedora23affected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
ubuntu ubuntu15.10affected
linux linux-kernelaffected4.4
linux linux-kernel4.4affected

References

CWEs

CWE-369

💬 Discuss CVE-2015-7513 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.