Bug 1327465 (CVE-2016-7908) - CVE-2016-7908 Qemu: net: Infinite loop in mcf_fec_do_tx()
Summary: CVE-2016-7908 Qemu: net: Infinite loop in mcf_fec_do_tx()
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2016-7908
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1381193
Blocks: 1326713
TreeView+ depends on / blocked
 
Reported: 2016-04-15 08:01 UTC by Adam Mariš
Modified: 2021-02-17 04:03 UTC (History)
42 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-16 10:24:41 UTC


Attachments (Terms of Use)

Description Adam Mariš 2016-04-15 08:01:35 UTC
Quick Emulator(Qemu) built with the ColdFire Fast Ethernet Controller emulator 
support is vulnerable to an infinite loop issue. It could occur while processing
packets on the transmit queue in 'mcf_fec_do_tx'.

A privileged user/process inside guest could use this issue to crash the Qemu process on the host leading to DoS.

Upstream patch
--------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg05557.html

Comment 1 Adam Mariš 2016-04-15 08:01:57 UTC
Acknowledgments:

Name: Li Qiang (Qihoo 360 Inc.)

Comment 3 Prasad J Pandit 2016-10-03 11:27:53 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1381193]

Comment 4 Andrej Nemec 2016-10-04 08:06:50 UTC
CVE assignment:

http://seclists.org/oss-sec/2016/q4/11


Note You need to log in before you can comment on or make changes to this bug.