CVE-2015-3256

polkit < 0.113 - Memory Corruption and Denial of Service via JavaScript Rule Evaluation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3256. PoCs published by puglia-ryan.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2015-3456 (VENOM), demonstrating a crash in QEMU v2.3.0 by flooding the floppy disk controller (FDC) with attacker-controlled bytes. The exploit includes a guest-side C program (`venom-crash.c`) that triggers the vulnerability, along with setup scripts and patching notes.

Description

PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "javascript rule evaluation."

Exploits (1)

nomisec WORKING POC
by puglia-ryan · poc
https://github.com/puglia-ryan/S-V-Project-Implementation-of-CVE-2015-3256

This repository contains a functional proof-of-concept for CVE-2015-3456 (VENOM), demonstrating a crash in QEMU v2.3.0 by flooding the floppy disk controller (FDC) with attacker-controlled bytes. The exploit includes a guest-side C program (`venom-crash.c`) that triggers the vulnerability, along with setup scripts and patching notes.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: QEMU v2.3.0
No auth needed
Prerequisites: QEMU v2.3.0 · Alpine Linux guest VM · floppy disk controller access
devstral-2 · analyzed May 19, 2026 Full analysis →

References (8)

Core 8
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1245684
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0189.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77356
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html
Various Sources mailing-list x_refsource_mlist
http://lists.freedesktop.org/archives/polkit-devel/2015-July/000432.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035023

Scores

EPSS 0.0008
EPSS Percentile 22.9%

Details

CWE
CWE-264
Status published
Products (3)
opensuse/opensuse 13.1
opensuse/opensuse 13.2
polkit_project/polkit < 0.112
Published Oct 26, 2015
Tracked Since Feb 18, 2026