Database/Kernel, userspace & hypervisor

QEMU / KVM / Xen (VENOM): VENOM: out-of-bounds write in the virtual Floppy Disk Controller
CVE-2015-3456Kernel, userspace & hypervisorcurated
Impact
VENOM: out-of-bounds write in the virtual Floppy Disk Controller - guest-to-host code execution; present even when the FDC is disabled in the guest config
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart. The origin of the "unused emulated device is still attack surface" lesson - audit and strip emulated devices from tenant VM templates
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.