Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1528396 - (CVE-2018-5748) CVE-2018-5748 libvirt: Resource exhaustion via qemuMonitorIORead() method
CVE-2018-5748 libvirt: Resource exhaustion via qemuMonitorIORead() method
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180116,reported=2...
: Reopened, Security
Depends On: 1535785 1550979 1550980 1566978
Blocks: 1528397
  Show dependency treegraph
 
Reported: 2017-12-21 13:34 EST by Pedro Sampaio
Modified: 2018-10-24 04:58 EDT (History)
18 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-10-24 04:58:14 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:1396 None None None 2018-05-14 12:11 EDT
Red Hat Product Errata RHSA-2018:1929 None None None 2018-06-19 00:56 EDT

  None (edit)
Description Pedro Sampaio 2017-12-21 13:34:15 EST
A flaw was found in Qemu. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to denial of service by exhaustion of memory resources.

References:

https://www.redhat.com/archives/libvir-list/2017-December/msg00749.html
Comment 1 Pedro Sampaio 2017-12-21 13:34:29 EST
Acknowledgments:

Name: Daniel P. Berrange (Red Hat), Peter Krempa (Red Hat)
Comment 2 Prasad J Pandit 2018-01-18 01:05:43 EST
Created libvirt tracking bugs for this issue:

Affects: fedora-all [bug 1535785]
Comment 3 Cedric Buissart 2018-01-24 09:36:48 EST
Although RHES-3 (RHGS) is shipped with libvirt, it does not use Qemu. As such, there is no qemu process running, and no vulnerable monitor socket created.
Comment 4 Fedora Update System 2018-03-01 11:23:28 EST
libvirt-3.7.0-4.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.
Comment 6 errata-xmlrpc 2018-05-14 12:11:22 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:1396 https://access.redhat.com/errata/RHSA-2018:1396
Comment 7 errata-xmlrpc 2018-06-19 00:55:50 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2018:1929 https://access.redhat.com/errata/RHSA-2018:1929

Note You need to log in before you can comment on or make changes to this bug.