CVE-2015-5278: Arista Eos

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

Affected products

  • Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Qemu Qemu: before 2.4.0.1 (fixed in 2.4.0.1)

Published 2020-01-23. Last modified 2026-06-17.