Quick emulator(Qemu) built with the LSI SAS1068 Host Bus emulation support, is vulnerable to an invalid memory access issue. It could occur while building configuration page headers in 'mptsas_config_manufacturing_1'. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host resulting in DoS. Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-08/msg04295.html -> https://lists.gnu.org/archive/html/qemu-devel/2016-08/msg04296.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/09/06/4
Acknowledgments: Name: Victor V (360.cn Marvel Team)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1373505]