Fedora Account System
Red Hat Associate
Red Hat Customer
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is vulnerable to an OOB read issue. It could occur while processing 'VIRTIO_GPU_CMD_SET_SCANOUT:' command. A guest user/process could use this flaw to crash the Qemu process instance resulting in Dos. Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=acfc4846508a02cc4c83aa27799fd7 -> http://git.qemu.org/?p=qemu.git;a=commit;h=2fe760554eb3769d70f608a158474f Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/12/20/2
Acknowledgments: Name: Hongzhenhao Marvel Team (360.cn Inc.)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1406392]