CVE-2015-8743: Debian Linux

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Qemu Qemu: up to and including 2.5.1

Published 2016-12-29. Last modified 2026-06-17.