CVE-2015-8817: Qemu

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS.

Affected products

  • Qemu Qemu: version 1.6.0 only; version 1.6.1 only; version 1.6.2 only; version 1.7.1 only; version 2.0.0 only; version 2.0.2 only; …

Published 2016-12-29. Last modified 2026-06-17.