Bug 1288532 (CVE-2016-1568)
Summary: | CVE-2016-1568 Qemu: ide: ahci use-after-free vulnerability in aio port commands | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | abaron, aortega, apevec, areis, ayoung, chrisw, dallan, eglynn, gkotton, jen, jjoyce, jschluet, knoel, lhh, lpeer, lsvaty, markmc, mburns, mgarciac, mkenneth, mrezanin, mst, osoukup, pbonzini, pgrist, ppandit, rbalakri, rbryant, sclewis, security-response-team, slong, tdecacqu, virt-maint, yeylon |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
A use-after-free flaw was found in the way QEMU's IDE AHCI emulator processed certain AHCI Native Command Queuing (NCQ) AIO commands. A privileged guest user could use this flaw to crash the QEMU process instance or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-01-28 20:33:14 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1297023, 1297024, 1297290, 1297291, 1297292, 1297293, 1297296, 1297297, 1297299, 1298395 | ||
Bug Blocks: | 1288546, 1298460 |
Description
Adam Mariš
2015-12-04 14:12:13 UTC
Statement: (none) Created xen tracking bugs for this issue: Affects: fedora-all [bug 1297024] Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1297023] qemu-2.4.1-6.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in the following products: OpenStack 7 For RHEL 7 Via RHSA-2016:0088 https://rhn.redhat.com/errata/RHSA-2016-0088.html This issue has been addressed in the following products: OpenStack 6 for RHEL 7 Via RHSA-2016:0087 https://rhn.redhat.com/errata/RHSA-2016-0087.html This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2016:0086 https://rhn.redhat.com/errata/RHSA-2016-0086.html This issue has been addressed in the following products: RHEV 3.6 For IBM Power Systems RHEV-H and Agents for RHEL-7 Via RHSA-2016:0084 https://rhn.redhat.com/errata/RHSA-2016-0084.html |