Bug 2203387 (CVE-2023-2680)

Summary: CVE-2023-2680 QEMU: hcd-ehci: DMA reentrancy issue (incomplete fix for CVE-2021-3750)
Product: [Other] Security Response Reporter: Mauro Matteo Cascella <mcascell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ddepaula, eglynn, jen, jferlan, jjoyce, jmaloy, knoel, lhh, mburns, mgarciac, mkenneth, mrezanin, mst, pbonzini, spower, virt-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2203388    
Bug Blocks: 2203420    

Description Mauro Matteo Cascella 2023-05-12 11:31:13 UTC
The QEMU flaw CVE-2021-3750 (bug 1999073) was declared fixed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2022:7967, released on Nov 15, 2022:

https://access.redhat.com/errata/RHSA-2022:7967

However, the erratum included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750. The CVE-2023-2680 was assigned to this incomplete fix and it is specific to the qemu-kvm packages produced by Red Hat. This issue and CVE-ID is not applicable to any upstream QEMU version or QEMU packages of any other vendor that are not directly based on Red Hat Enterprise Linux packages.

For more information about the original flaw, refer to the CVE page or bug linked above.

Comment 3 errata-xmlrpc 2023-11-07 08:14:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6368 https://access.redhat.com/errata/RHSA-2023:6368