Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3214

27
FAUCET Score

CVE-2015-3214 describes a heap overflow vulnerability in the i8254 Programmable Interrupt Timer (PIT) emulation within the Linux kernel (before 2.6.33) and QEMU (before 2.3.1). This flaw, stemming from improper handling of read/write lengths, could allow a guest OS user to execute arbitrary code on the host system. With a CVSS score of 6.9, it's considered high severity, requiring local access and medium attack complexity to achieve complete confidentiality, integrity, and availability compromise. While not listed on CISA's KEV catalog, an ExploitDB entry (EDB-37990) exists detailing a QEMU heap overflow, suggesting publicly available exploit code. However, there is no evidence of active exploitation, and community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.3.0CPE matchmatch criteria
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
<= 2.6.32CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.12CPE matchmatch criteria
cpe:2.3:o:arista:eos:4.12:*:*:*:*:*:*:*
4.13CPE matchmatch criteria
cpe:2.3:o:arista:eos:4.13:*:*:*:*:*:*:*
4.14CPE matchmatch criteria
cpe:2.3:o:arista:eos:4.14:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.59%
Probability of exploitation in next 30 days
EPSS Percentile
73.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-37990 · Aug 27, 2015
This CVE's current EPSS score of 0.0159 is in the 94th percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-10:1.5.3-86.el7_1.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7Fixed in: qemu-kvm-rhev-10:2.1.2-23.el7_1.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7Fixed in: qemu-kvm-rhev-10:2.1.2-23.el7_1.6
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-7Fixed in: qemu-kvm-rhev-10:2.1.2-23.el7_1.6
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kvm

Vendor Advisories (1)

redhatCVE-2015-3214Moderate

qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function

Jun 16, 2015

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
mirror.linux.org.au / linux/kernel/v2.6/ChangeLog-2.6.33
Broken LinkVendor Advisory
rhn.redhat.com / errata/RHSA-2015-1507.html
Issue TrackingThird Party Advisory
rhn.redhat.com / errata/RHSA-2015-1508.html
Issue TrackingThird Party Advisory
rhn.redhat.com / errata/RHSA-2015-1512.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / torvalds/linux/commit/ee73f656a604d5aa9df86a97102e4e462dd79924
PatchThird Party Advisory
security.gentoo.org / glsa/201510-02
Issue TrackingThird Party Advisory
support.lenovo.com / product_security/qemu
Third Party Advisory
support.lenovo.com / us/en/product_security/qemu
Third Party Advisory
arista.com / en/support/advisories-notices/security-advisories/1180-security-advisory-13
Third Party Advisory
exploit-db.com / exploits/37990
Third Party AdvisoryVDB Entry
mail-archive.com / qemu-devel%40nongnu.org/msg304138.html
debian.org / security/2015/dsa-3348
Issue TrackingThird Party Advisory
openwall.com / lists/oss-security/2015/06/25/7
Mailing List
securityfocus.com / bid/75273
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032598
Third Party AdvisoryVDB Entry