Bug 1553402 (CVE-2018-7858)

Summary: CVE-2018-7858 QEMU: cirrus: OOB access when updating VGA display
Product: [Other] Security Response Reporter: Prasad Pandit <ppandit>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ailan, amit, apevec, areis, berrange, cfergeau, chrisw, drjones, dwmw2, imammedo, itamar, jen, jforbes, jjoyce, jschluet, kbasil, knoel, lhh, lpeer, markmc, m.a.young, mburns, mkenneth, mrezanin, mst, pbonzini, rbryant, rjones, rkrcmar, robinlee.sysu, sclewis, slinaber, sparks, srevivo, tdecacqu, virt-maint, virt-maint, vkuznets, xen-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:17:22 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1553403, 1553404, 1553667, 1553668, 1553669, 1553670, 1553671, 1553672, 1553673, 1553674, 1553675, 1553689, 1553690, 1566874, 1566878, 1567913    
Bug Blocks: 1549764    

Description Prasad Pandit 2018-03-08 19:38:21 UTC
Quick emulator(QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is
vulnerable to an out-of-bounds access issue. It could occur while updating
VGA display, after guest has adjusted the display dimensions.

A privileged user inside guest could use this flaw to crash the Qemu process
resulting in DoS.

Upstream patch:
---------------
  -> https://lists.nongnu.org/archive/html/qemu-devel/2018-03/msg02174.html

Reference:
----------
  -> http://www.openwall.com/lists/oss-security/2018/03/09/1

Comment 1 Prasad Pandit 2018-03-08 19:39:05 UTC
Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1553403]


Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1553404]

Comment 3 Prasad Pandit 2018-03-09 09:53:23 UTC
Acknowledgments:

Name: Ross Lagerwall (Citrix.com)

Comment 7 errata-xmlrpc 2018-05-10 16:04:48 UTC
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for RHEL-7

Via RHSA-2018:1369 https://access.redhat.com/errata/RHSA-2018:1369

Comment 8 errata-xmlrpc 2018-05-14 14:36:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:1416 https://access.redhat.com/errata/RHSA-2018:1416

Comment 9 Joshua Padman 2018-06-07 04:50:20 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 8
Via RHSA-2018:1646 https://access.redhat.com/errata/RHSA-2018:1646

  Red Hat OpenStack Platform 9
Via RHSA-2018:1645 https://access.redhat.com/errata/RHSA-2018:1645

  Red Hat OpenStack Platform 10
Via RHSA-2018:1644 https://access.redhat.com/errata/RHSA-2018:1644

  Red Hat OpenStack Platform 12
Via RHSA-2018:1643 https://access.redhat.com/errata/RHSA-2018:1643

Comment 10 errata-xmlrpc 2018-07-10 17:52:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2018:2162 https://access.redhat.com/errata/RHSA-2018:2162