CVE-2015-3214: Arista Eos
Medium severity, CVSS 6.9. EPSS: 1.6% chance of exploitation in the next 30 days.
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
Affected products
- Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Lenovo Emc PX12-400r Ivx: before 1.0.10.33264 (fixed in 1.0.10.33264)
- Lenovo Emc PX12-450r Ivx: before 1.0.10.33264 (fixed in 1.0.10.33264)
- Linux Linux Kernel: up to and including 2.6.32
- Qemu Qemu: up to and including 2.3.0
- Red Hat Enterprise Linux Compute Node Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
- Red Hat Enterprise Linux For Power Big Endian Eus: version 7.1_ppc64 only; version 7.2_ppc64 only; version 7.3_ppc64 only; version 7.4_ppc64 only; version 7.5_ppc64 only; version 7.6_ppc64 only; …
- Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux Server From Rhui: version 7.0 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat Openstack: version 5.0 only; version 6.0 only
- Red Hat Virtualization: version 3.0 only
Published 2015-08-31. Last modified 2026-06-17.