The fix for CVE-2016-3712 introduced a regression and we'll have to push a new update.
From the upstream patch:
From: Gerd Hoffmann <firstname.lastname@example.org>
Subject: [Qemu-devel] [PATCH] vga: add sr_vbe register set
Commit "fd3c136 vga: make sure vga register setup for vbe stays intact
(CVE-2016-3712)." causes a regression. The win7 installer is unhappy
because it can't freely modify vga registers any more while in vbe mode.
This patch introduces a new sr_vbe register set. The vbe_update_vgaregs
will fill sr_vbe instead of sr. Normal vga register reads and
writes go to sr. Any sr register read access happens through a new
sr() helper function which will read from sr_vbe with vbe active and
from sr otherwise.
This way we can allow guests update sr registers as they want, without
allowing them disrupt vbe video modes that way.
Reported-by: Thomas Lamprecht <email@example.com>
Signed-off-by: Gerd Hoffmann <firstname.lastname@example.org>
Fix included in qemu-kvm-rhev-2.6.0-7.el7
Reproduced on 7.3 host with
Trying to install win7/win2008r2 guests, results:
iso:en_windows_7_ultimate_with_sp1_x86_dvd_u_677460.iso result: stuck at "starting windows"
iso:en_windows_7_ultimate_with_sp1_x64_dvd_u_677332.iso result: stuck at "starting windows"
iso:en_windows_server_2008_r2_standard_enterprise_datacenter_and_web_with_sp1_x64_dvd_617601.iso result: stuck at "starting windows"
Install win10 guests for comparing, win10 guests install and work well, isos used:
Verify against qemu-kvm-rhev-2.6.0-7.el7.x86_64
Both windows7/win2008r2 guests install and work well.
Install win10 guests for comparing, win10 guests install and work well also.
Move to verified per comment 4
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.