Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-7295

Published: 9 November 2015

hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.

Priority

Low

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
precise Does not exist

trusty
Released (2.0.0+dfsg-2ubuntu1.21)
upstream
Released (1:2.4+dfsg-4)
vivid
Released (1:2.2+dfsg-5expubuntu9.7)
wily
Released (1:2.3+dfsg-5ubuntu9.1)
Patches:
upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=ce317461573bac12b10d67699b4ddf1f97cf066c
upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=29b9f5efd78ae0f9cc02dd169b6e80d2c404bade
upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=0cf33fb6b49a19de32859e2cdc6021334f448fb3
other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04729.html
other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04730.html
other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04731.html
qemu-kvm
Launchpad, Ubuntu, Debian
precise
Released (1.0+noroms-0ubuntu14.26)
trusty Does not exist

upstream Needed

vivid Does not exist

wily Does not exist