CVE-2015-5745: Arista Eos

Medium severity, CVSS 6.5. EPSS: 3% chance of exploitation in the next 30 days.

Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.

Affected products

  • Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Qemu Qemu: before 2.4.0 (fixed in 2.4.0)

Published 2020-01-23. Last modified 2026-06-17.