Quick emulator(Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS OR potentially execute arbitrary code on the host with privileges of Qemu process on the host. Upstream patch -------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg00015.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/01/6
Acknowledgments: Name: Wjjzhang (Tencent.com Inc.), Li Qiang (360.cn Inc.)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1418206]
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1418243]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0309 https://rhn.redhat.com/errata/RHSA-2017-0309.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Via RHSA-2017:0334 https://rhn.redhat.com/errata/RHSA-2017-0334.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 Via RHSA-2017:0333 https://rhn.redhat.com/errata/RHSA-2017-0333.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Via RHSA-2017:0332 https://rhn.redhat.com/errata/RHSA-2017-0332.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Via RHSA-2017:0331 https://rhn.redhat.com/errata/RHSA-2017-0331.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 8.0 (Liberty) Via RHSA-2017:0330 https://rhn.redhat.com/errata/RHSA-2017-0330.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2017:0329 https://rhn.redhat.com/errata/RHSA-2017-0329.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2017:0328 https://rhn.redhat.com/errata/RHSA-2017-0328.html
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-6 Via RHSA-2017:0344 https://rhn.redhat.com/errata/RHSA-2017-0344.html
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-7 RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:0350 https://rhn.redhat.com/errata/RHSA-2017-0350.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0396 https://rhn.redhat.com/errata/RHSA-2017-0396.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2017:0454 https://rhn.redhat.com/errata/RHSA-2017-0454.html