Red Hat Bugzilla – Bug 1368990
CVE-2016-6834 Qemu: net: vmxnet3: an infinite loop during packet fragmentation
Last modified: 2018-07-18 10:59:26 EDT
Quick Emulator(Qemu) built with the VMWARE VMXNET3 NIC device support, with network abstraction layer is vulnerable to an infinite loop issue. It could occur while fragmenting packets in the device. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS. Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=ead315e43ea0c2ca3491209c6c8db8ce3f2bbe05 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/08/18/7
Acknowledgments: Name: Li Qiang (Qihoo 360 Inc.)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1368991]