Back to bug 1304794

Who When What Removed Added
Adam Mariš 2016-02-04 15:56:25 UTC CC security-response-team
Red Hat Bugzilla 2016-02-04 15:56:25 UTC Doc Type --- Bug Fix
Adam Mariš 2016-02-04 16:13:02 UTC Blocks 1304800
Prasad Pandit 2016-02-16 10:42:22 UTC Priority medium low
CC prasad
Doc Text Qemu emulator built with the USB OHCI emulation support is vulnerable to a null pointer dereference issue. It could occur when OHCI transitions to a OHCI_USB_OPERATIONAL state,
leading to creation of multiple eof timers. A privileged user inside guest could use this flaw to crash the Qemu process on the host, resulting in DoS.
Whiteboard impact=moderate,public=no,reported=20160204,source=researcher,cvss2=5.2/AV:A/AC:M/Au:S/C:N/I:N/A:C,cwe=CWE-400,rhel-5/kvm=new,rhel-5/xen=new,rhel-6/qemu-kvm=new,rhel-6/qemu-kvm-rhev=new,rhel-7/qemu-kvm=new,rhel-7/qemu-kvm-rhev=new,openstack-5/qemu-kvm-rhev=new,openstack-6/qemu-kvm-rhev=new,openstack-7/qemu-kvm-rhev=new,openstack-8/qemu-kvm-rhev=new,rhev-m-3/qemu-kvm-rhev=new,fedora-all/qemu=affected,fedora-all/xen=affected impact=low,public=20160216,reported=20160204,source=researcher,cvss2=2.3/AV:A/AC:M/Au:S/C:N/I:N/A:P,cwe=CWE-476,rhel-5/kvm=wontfix,rhel-5/xen=wontfix,rhel-6/qemu-kvm=wontfix,rhel-6/qemu-kvm-rhev=wontfix,rhel-7/qemu-kvm=wontfix,rhel-7/qemu-kvm-rhev=wontfix,openstack-5/qemu-kvm-rhev=wontfix,openstack-6/qemu-kvm-rhev=wontfix,openstack-7/qemu-kvm-rhev=wontfix,openstack-8/qemu-kvm-rhev=wontfix,fedora-all/qemu=affected,fedora-all/xen=affected
Severity medium low
Prasad Pandit 2016-02-16 10:48:19 UTC Summary EMBARGOED qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV
Prasad Pandit 2016-02-16 10:48:30 UTC Group security, qe_staff
Prasad Pandit 2016-02-16 10:48:49 UTC Depends On 1308881
Prasad Pandit 2016-02-16 10:49:09 UTC Depends On 1308882
Prasad Pandit 2016-02-16 10:52:45 UTC Summary qemu: Holding multiple eof_timers at the same time in ohci usb mode leads to SIGSEGV Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
Andrej Nemec 2016-02-16 15:16:03 UTC Alias CVE-2016-2391
Andrej Nemec 2016-02-16 15:16:14 UTC Summary Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference CVE-2016-2391 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference
Summer Long 2016-03-13 23:09:02 UTC CC slong
Doc Text Qemu emulator built with the USB OHCI emulation support is vulnerable to a null pointer dereference issue. It could occur when OHCI transitions to a OHCI_USB_OPERATIONAL state,
leading to creation of multiple eof timers. A privileged user inside guest could use this flaw to crash the Qemu process on the host, resulting in DoS.
A NULL pointer dereference flaw was found in the QEMU emulator built with USB OHCI emulation support. The flaw could occur when OHCI transitions to the OHCI_USB_OPERATIONAL state, leading to the creation of multiple EOF timers. A privileged user inside a guest could exploit this flaw to crash the QEMU process on the host (denial of service).
John Skeoch 2016-04-18 07:40:47 UTC CC yeylon srevivo
Perry Myers 2016-04-19 01:11:28 UTC CC pmyers
Scott Herold 2017-09-12 15:24:51 UTC CC sherold
PnT Account Manager 2018-01-30 23:55:51 UTC CC aortega
PnT Account Manager 2018-07-18 14:49:00 UTC CC rbalakri
PnT Account Manager 2018-11-05 22:42:40 UTC CC ylavi
Gil Klein 2019-04-14 12:37:59 UTC CC gklein
Product Security DevOps Team 2019-06-08 02:48:10 UTC Status NEW CLOSED
Resolution --- WONTFIX
Last Closed 2019-06-08 02:48:10 UTC
Product Security DevOps Team 2019-09-29 13:43:28 UTC Whiteboard impact=low,public=20160216,reported=20160204,source=researcher,cvss2=2.3/AV:A/AC:M/Au:S/C:N/I:N/A:P,cwe=CWE-476,rhel-5/kvm=wontfix,rhel-5/xen=wontfix,rhel-6/qemu-kvm=wontfix,rhel-6/qemu-kvm-rhev=wontfix,rhel-7/qemu-kvm=wontfix,rhel-7/qemu-kvm-rhev=wontfix,openstack-5/qemu-kvm-rhev=wontfix,openstack-6/qemu-kvm-rhev=wontfix,openstack-7/qemu-kvm-rhev=wontfix,openstack-8/qemu-kvm-rhev=wontfix,fedora-all/qemu=affected,fedora-all/xen=affected

Back to bug 1304794