CVE-2015-5165: Arista Eos
High severity, CVSS 9.3. EPSS: 13.3% chance of exploitation in the next 30 days.
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Affected products
- Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fedoraproject Fedora: version 21 only; version 22 only
- Oracle Linux: version 7 only
- Red Hat Enterprise Linux Compute Node Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.7 only
- Red Hat Enterprise Linux Eus Compute Node: version 6.7 only
- Red Hat Enterprise Linux For Power Big Endian: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux For Power Big Endian Eus: version 6.7_ppc64 only; version 7.1_ppc64 only; version 7.2_ppc64 only; version 7.3_ppc64 only; version 7.4_ppc64 only; version 7.5_ppc64 only; …
- Red Hat Enterprise Linux For Scientific Computing: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux Server Eus From Rhui: version 6.7 only
- Red Hat Enterprise Linux Server From Rhui: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat Openstack: version 5.0 only; version 6.0 only
- Red Hat Virtualization: version 3.0 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Server: version 10 only; version 11 only
- Xen Xen: up to and including 4.5.0; version 4.5.1 only
Published 2015-08-12. Last modified 2026-06-17.