CVE-2015-5166 Information

Description

Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices which allows local HVM guest users to gain privileges by unplugging a block device twice.

Reference

http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html http://www.securityfocus.com/bid/76152 http://www.securitytracker.com/id/1033175 http://xenbits.xen.org/xsa/advisory-139.html

Share on: