CVE-2015-5225: Fedoraproject Fedora

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.

Affected products

  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Qemu Qemu: up to and including 2.4.0
  • Red Hat Openstack: version 5.0 only; version 6.0 only; version 7.0 only

Published 2015-11-06. Last modified 2026-06-17.