Bug 577218 - (CVE-2010-0741) CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver
CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux vir...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
reported=20091022,public=20091022,sou...
: Security
Depends On: 545136 577243
Blocks:
  Show dependency treegraph
 
Reported: 2010-03-26 09:35 EDT by Petr Matousek
Modified: 2016-04-26 12:17 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-04-10 16:58:14 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Petr Matousek 2010-03-26 09:35:31 EDT
A flaw was found in the way the QEMU-KVM handled erroneous data provided
by the guest Linux virtio-net driver. Due deficiency in the implementation of
the TSO (TCP segment offloading), the guest's virtio-net driver transmitted
improper data to the particular QEMU-KVM process on the host, resulting in its
termination. A remote attacker could use this flaw to cause denial of service
(guest crash) by sending certain, specially-crafted data to arbitrary open port
on the target guest system.

A remote attacker could exploit this to crash guests which use virtio
networking on Linux kernels earlier than 2.6.26.
Comment 3 errata-xmlrpc 2010-03-30 03:51:25 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0271 https://rhn.redhat.com/errata/RHSA-2010-0271.html
Comment 7 Yewei Shao 2010-06-17 10:41:14 EDT
Change the bug to verified according to the bug 577243#c7.
Comment 8 Yewei Shao 2010-06-17 10:42:14 EDT
Update the comment #7:

Change the bug to verified according to the bug 577243#c4.
Comment 9 errata-xmlrpc 2010-06-22 09:54:08 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Virtualization for RHEL-5

Via RHSA-2010:0476 https://rhn.redhat.com/errata/RHSA-2010-0476.html

Note You need to log in before you can comment on or make changes to this bug.