CVE-2007-2894

Bochs 2.3 - Denial of Service via Floppy Disk Controller

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2894. PoCs published by Tavis Ormandy.

AI-analyzed exploit summary This exploit targets a heap-based buffer overflow and divide-by-zero vulnerability in Bochs. It uses direct port I/O operations to trigger the vulnerability, potentially leading to arbitrary code execution or denial-of-service conditions.

Description

The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tavis Ormandy · cdoslinux
https://www.exploit-db.com/exploits/30110

This exploit targets a heap-based buffer overflow and divide-by-zero vulnerability in Bochs. It uses direct port I/O operations to trigger the vulnerability, potentially leading to arbitrary code execution or denial-of-service conditions.

Classification
Working Poc 90%
Attack Type
Rce | Dos
Complexity
Moderate
Reliability
Reliable
Target: Bochs (version not specified)
No auth needed
Prerequisites: Local access to the system running Bochs · Sufficient privileges to execute I/O operations
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=188148
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27715
Third Party Advisory x_refsource_misc
http://taviso.decsystem.org/virtsec.pdf
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/42119
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200711-21.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24246
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1936
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34513
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25470

Scores

EPSS 0.0073
EPSS Percentile 49.3%

Details

Status published
Products (1)
bochs_project/bochs 2.3
Published May 30, 2007
Tracked Since Feb 18, 2026