CVE-2015-6815: Arista Eos

Low severity, CVSS 3.5. EPSS: 1% chance of exploitation in the next 30 days.

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

Affected products

  • Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Novell Suse Linux Enterprise Debuginfo: version 11.0 only
  • Novell Suse Linux Enterprise Desktop: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
  • Qemu Qemu: before 2.4.0.1 (fixed in 2.4.0.1)
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Openstack: version 5.0 only; version 6.0 only; version 7.0 only
  • Xen Xen: version 4.4.3 only; version 4.5.1 only

Published 2020-01-31. Last modified 2026-06-17.