Red Hat Bugzilla – Bug 1414209
CVE-2017-5526 Qemu: audio: memory leakage in es1370 device
Last modified: 2018-07-18 11:11:50 EDT
Quick Emulator(Qemu) built with the ES1370 audio device emulation support is vulnerable to a memory leakage issue. It could occur while doing a device unplug operation; Doing so repeatedly would result in leaking host memory, affecting other services on the host. A privileged user inside guest could use this flaw to cause a DoS and/or potentially crash the Qemu process on the host. Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg01742.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/01/18/8
Acknowledgments: Name: Li Qiang (360.cn Inc.) Jiangxin (PSIRT Huawei Inc.)
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1414211]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1414210]