Database/Kernel, userspace & hypervisor

QEMU / KVM / Xen (VENOM): VENOM: out-of-bounds write in the virtual Floppy Disk Controller
CVSS 2.0CVE-2015-3456Kernel, userspace & hypervisorcurated
Impact
VENOM: out-of-bounds write in the virtual Floppy Disk Controller - guest-to-host code execution; present even when the FDC is disabled in the guest config
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart. The origin of the "unused emulated device is still attack surface" lesson - audit and strip emulated devices from tenant VM templates
References
Related entries
- Xen (shadow paging): x86 shadow paging arbitrary pointer dereference - host crash or worseCVE-2022-42335 · Xen (shadow paging)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2022-50619 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2023-54144 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2023-54261 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Xen (x86 speculation): Xen hypercall page unsafe against speculative attacks - guest leaks hypervisor memoryCVE-2024-53241 · Xen (x86 speculation)Unscored
- Xen (VT-d passthrough): Deadlock potential with VT-d and legacy PCI device pass-through - host hangCVE-2025-1713 · Xen (VT-d passthrough)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.