Medium severity5.5NVD Advisory· Published Apr 12, 2016· Updated May 6, 2026
CVE-2015-5158
CVE-2015-5158
Description
Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor block.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/76016nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1033095nvdThird Party AdvisoryVDB Entry
- lists.nongnu.org/archive/html/qemu-devel/2015-07/msg04558.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201510-02nvdThird Party Advisory
News mentions
0No linked articles in our index yet.