Quick Emulator(Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while hotunplugging the device, as it does not release the memory allocated at initialisation. A guest user/process could use this issue to leak host memory, resulting in DoS for host. Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=d710e1e7bd3d5bfc26b631f02ae87901ebe646b0 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/06/06/3
Acknowledgments: Name: Li Qiang (Qihoo 360 Gear Team)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1459137]
qemu-2.7.1-7.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Red Hat OpenStack Platform 11.0 (Ocata) Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Red Hat OpenStack Platform 8.0 (Liberty) Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2017:2408 https://access.redhat.com/errata/RHSA-2017:2408
This issue has been addressed in the following products: RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:2392 https://access.redhat.com/errata/RHSA-2017:2392