Hide Forgot
Quick Emulator(Qemu) built with the ES1370 audio device emulation support is vulnerable to a memory leakage issue. It could occur while doing a device unplug operation; Doing so repeatedly would result in leaking host memory, affecting other services on the host. A privileged user inside guest could use this flaw to cause a DoS and/or potentially crash the Qemu process on the host. Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg01742.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/01/18/8
Acknowledgments: Name: Li Qiang (360.cn Inc.) Jiangxin (PSIRT Huawei Inc.)
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1414211]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1414210]