CVE-2015-3214 describes a heap overflow vulnerability in the i8254 Programmable Interrupt Timer (PIT) emulation within the Linux kernel (before 2.6.33) and QEMU (before 2.3.1). This flaw, stemming from improper handling of read/write lengths, could allow a guest OS user to execute arbitrary code on the host system. With a CVSS score of 6.9, it's considered high severity, requiring local access and medium attack complexity to achieve complete confidentiality, integrity, and availability compromise. While not listed on CISA's KEV catalog, an ExploitDB entry (EDB-37990) exists detailing a QEMU heap overflow, suggesting publicly available exploit code. However, there is no evidence of active exploitation, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
<= 2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.12CPE matchmatch criteria | cpe:2.3:o:arista:eos:4.12:*:*:*:*:*:*:* | ||
4.13CPE matchmatch criteria | cpe:2.3:o:arista:eos:4.13:*:*:*:*:*:*:* | ||
4.14CPE matchmatch criteria | cpe:2.3:o:arista:eos:4.14:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.