CVE-2015-4106 describes a privilege escalation vulnerability in QEMU affecting Canonical, Citrix, Debian, Fedora, QEMU, and SUSE products. It stems from insufficient write access restrictions to the PCI config space for specific PCI pass-through devices. This local vulnerability, with low attack complexity, could allow x86 HVM guests to gain privileges, cause a denial of service, or leak sensitive information. There is no evidence of active exploitation, no public exploit code, and minimal community discussion, with its EPSS and FAUCET scores indicating low exploitability and risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.1CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.