CVE-2015-4037: Qemu

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.

Affected products

  • Qemu Qemu: up to and including 2.3.0

Published 2015-08-26. Last modified 2026-06-17.