Red Hat Bugzilla – Bug 1636773
CVE-2018-17962 Qemu: pcnet: integer overflow leads to buffer overflow
Last modified: 2018-10-09 11:42:14 EDT
Qemu emulator built with the AMD PC-Net II (Am79C970A) emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS. Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2018-09/msg03268.html Reference: ---------- -> https://www.openwall.com/lists/oss-security/2018/10/08/1
Acknowledgments: Name: Daniel Shapira (Twistlock), Arash Tohidi
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1636775] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1636776]
*** Bug 1613561 has been marked as a duplicate of this bug. ***