Hide Forgot
A stack-based buffer overflow flaw was found in QEMU's gem_receive() function. When GEM_NWCFG_STRIP_FCS was not set, gem_receive() would copy packet data to rxbuf[2048], resulting in a buffer overflow if the length of a packet was more than 2048. Acknowledgements: Red Hat would like to thank Ling Liu of Qihoo 360 Inc. for reporting this issue.
This turned out to be a security non-issue. -> https://bugzilla.redhat.com/show_bug.cgi?id=1297427#c3