Quick emulator(Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS OR potentially execute arbitrary code on the host with privileges of Qemu process on the host. Upstream patch -------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg04700.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/21/1
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1425420]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1425419]
External References: https://xenbits.xen.org/xsa/advisory-209.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Via RHSA-2017:0334 https://rhn.redhat.com/errata/RHSA-2017-0334.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 Via RHSA-2017:0333 https://rhn.redhat.com/errata/RHSA-2017-0333.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Via RHSA-2017:0332 https://rhn.redhat.com/errata/RHSA-2017-0332.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Via RHSA-2017:0331 https://rhn.redhat.com/errata/RHSA-2017-0331.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 8.0 (Liberty) Via RHSA-2017:0330 https://rhn.redhat.com/errata/RHSA-2017-0330.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2017:0329 https://rhn.redhat.com/errata/RHSA-2017-0329.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2017:0328 https://rhn.redhat.com/errata/RHSA-2017-0328.html
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-6 Via RHSA-2017:0351 https://rhn.redhat.com/errata/RHSA-2017-0351.html
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-7 RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:0350 https://rhn.redhat.com/errata/RHSA-2017-0350.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0352 https://rhn.redhat.com/errata/RHSA-2017-0352.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0396 https://rhn.redhat.com/errata/RHSA-2017-0396.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2017:0454 https://rhn.redhat.com/errata/RHSA-2017-0454.html