Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1340924 - (CVE-2016-5126) CVE-2016-5126 Qemu: block: iscsi: buffer overflow in iscsi_aio_ioctl
CVE-2016-5126 Qemu: block: iscsi: buffer overflow in iscsi_aio_ioctl
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160524,repor...
: Security
Depends On: 1340925 1340929 1340930 1358996 1358997 1359743 1359744 1359745 1359747 1363573 1363574
Blocks: 1340774 1366416
  Show dependency treegraph
 
Reported: 2016-05-30 13:36 EDT by Prasad J Pandit
Modified: 2016-12-14 23:35 EST (History)
25 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Quick Emulator(QEMU) built with the Block driver for iSCSI images support (virtio-blk) is vulnerable to a heap-based buffer overflow issue. The flaw could occur while processing iSCSI asynchronous I/O ioctl(2) calls. A user inside a guest could exploit this flaw to crash the QEMU process resulting in denial of service, or potentially leverage it to execute arbitrary code with QEMU-process privileges on the host.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-12-14 23:35:30 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:1606 normal SHIPPED_LIVE Moderate: qemu-kvm security update 2016-08-11 19:08:14 EDT
Red Hat Product Errata RHSA-2016:1607 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security update 2016-08-12 14:11:58 EDT
Red Hat Product Errata RHSA-2016:1653 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security update 2016-08-23 06:14:36 EDT
Red Hat Product Errata RHSA-2016:1654 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security update 2016-08-23 06:14:29 EDT
Red Hat Product Errata RHSA-2016:1655 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security update 2016-08-23 06:14:21 EDT
Red Hat Product Errata RHSA-2016:1756 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security and bug fix update 2016-08-24 05:09:40 EDT
Red Hat Product Errata RHSA-2016:1763 normal SHIPPED_LIVE Moderate: qemu-kvm-rhev security update 2016-08-24 13:10:17 EDT

  None (edit)
Description Prasad J Pandit 2016-05-30 13:36:23 EDT
Quick Emulator(Qemu) built with the Block driver for iSCSI images support
(virtio-blk) is vulnerable to a heap buffer overflow flaw. It could occur
while processing iSCSI asynchronous I/O ioctl(2) calls.

A user inside guest could use this flaw to crash the Qemu process resulting
in DoS OR potentially leverage it to execute arbitrary code with privileges
of the Qemu process on the host.

Upstream patch:
---------------
  -> https://lists.gnu.org/archive/html/qemu-block/2016-05/msg00779.html

Reference:
----------
  -> http://www.openwall.com/lists/oss-security/2016/05/30/6
Comment 1 Prasad J Pandit 2016-05-30 13:38:28 EDT
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1340925]
Comment 5 Fedora Update System 2016-06-25 15:25:41 EDT
qemu-2.6.0-4.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Comment 10 errata-xmlrpc 2016-08-11 15:08:25 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2016:1606 https://rhn.redhat.com/errata/RHSA-2016-1606.html
Comment 11 errata-xmlrpc 2016-08-12 10:12:12 EDT
This issue has been addressed in the following products:

  RHEV-H and Agents for RHEL-7

Via RHSA-2016:1607 https://rhn.redhat.com/errata/RHSA-2016-1607.html
Comment 12 errata-xmlrpc 2016-08-23 02:14:53 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7

Via RHSA-2016:1655 https://rhn.redhat.com/errata/RHSA-2016-1655.html
Comment 13 errata-xmlrpc 2016-08-23 02:16:02 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7

Via RHSA-2016:1654 https://rhn.redhat.com/errata/RHSA-2016-1654.html
Comment 14 errata-xmlrpc 2016-08-23 02:17:10 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7

Via RHSA-2016:1653 https://rhn.redhat.com/errata/RHSA-2016-1653.html
Comment 15 errata-xmlrpc 2016-08-24 01:09:50 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 8.0 (Liberty)

Via RHSA-2016:1756 https://rhn.redhat.com/errata/RHSA-2016-1756.html
Comment 16 errata-xmlrpc 2016-08-24 09:10:47 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 9.0 (Mitaka)

Via RHSA-2016:1763 https://rhn.redhat.com/errata/RHSA-2016-1763.html

Note You need to log in before you can comment on or make changes to this bug.