Red Hat Bugzilla – Bug 1636712
CVE-2018-17958 Qemu: rtl8139: integer overflow leads to buffer overflow
Last modified: 2018-10-09 10:44:07 EDT
Qemu emulator built with the RTL8139 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS. Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2018-09/msg03269.html Reference: ---------- -> https://www.openwall.com/lists/oss-security/2018/10/08/1
Acknowledgments: Name: Daniel Shapira (Twistlock), Arash Tohidi
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1636729] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1636730]