Red Hat Bugzilla – Bug 1615637
CVE-2018-15746 Qemu: seccomp: blacklist is not applied to all threads
Last modified: 2018-10-24 02:43:11 EDT
An issue was found in the way QEMU implements Seccomp sandboxing. In that, all QEMU threads are not bound by the sandbox. A guest user/process maybe be able to use this flaw to invoke prohibited system calls on a host, resulting in guest crash. Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2018-08/msg04892.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2018/08/28/6 -> https://lists.gnu.org/archive/html/qemu-devel/2018-08/msg02289.html
Acknowledgments: Name: Jann Horn (Google.com)
Created qemu tracking bugs for this issue: Affects: epel-7 [bug 1618358] Affects: fedora-all [bug 1618357]