Bug 1031702 (CVE-2013-4592)

Summary: CVE-2013-4592 kernel: kvm: memory leak when memory slot is moved with assigned device
Product: [Other] Security Response Reporter: Petr Matousek <pmatouse>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aquini, areis, bhu, dhoward, ehabkost, fhrbata, gansalmon, iboverma, itamar, jforbes, jkacur, jonathan, jross, jwboyer, kernel-maint, kernel-mgr, knoel, lgoncalv, madhu.chinakonda, marcel, matt, mcressma, mkenneth, mst, mtosatti, nobody, rt-maint, virt-maint, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20121210,reported=20130725,source=redhat,cvss2=4/AV:L/AC:H/Au:N/C:N/I:N/A:C,cwe=CWE-401[auto],rhel-5/kvm=wontfix,rhel-6/kernel=affected,mrg-2/realtime-kernel=notaffected,fedora-all/kernel=notaffected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 978472    
Bug Blocks: 1031705    

Description Petr Matousek 2013-11-18 15:10:11 UTC
When a user memory slot is moved (ie. the base_gfn changes), iommu pages are neither unpinned nor unmapped.  The memory for these pages then cannot be recovered without rebooting the system.

Local user with ability to assign device (with access to PCI sysfs files for a device) could use this flaw to DoS the system.

Upstream fixes:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=12d6e7538e2d418c08f082b1b44ffa5fb7270ed8
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e40f193f5bb022e927a57a4f5d5194e4f12ddb74

Comment 1 errata-xmlrpc 2013-11-21 20:37:15 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1645 https://rhn.redhat.com/errata/RHSA-2013-1645.html