CVE-2015-3456: Qemu

High severity, CVSS 7.7. EPSS: 15.3% chance of exploitation in the next 30 days.

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

Affected products

  • Qemu Qemu: up to and including 2.3.0
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Virtualization: version 3.0 only
  • Red Hat Openstack: version 4.0 only; version 5.0 only; version 6.0 only; version 7.0 only
  • Xen Xen: version 4.5.0 only

Published 2015-05-13. Last modified 2026-06-17.