SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-5165

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

HIGH 9.3EPSS 13.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
13.29% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-908
Affected
xen/xen · fedoraproject/fedora · suse/linux enterprise debuginfo · suse/linux enterprise server · debian/debian linux · redhat/openstack · redhat/virtualization · redhat/enterprise linux compute node eus · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux eus compute node · redhat/enterprise linux for power big endian · redhat/enterprise linux for power big endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server eus from rhui · redhat/enterprise linux server from rhui · redhat/enterprise linux server tus · +4 more
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.