Bug 577218 (CVE-2010-0741) - CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver
Summary: CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux vir...
Status: CLOSED ERRATA
Alias: CVE-2010-0741
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: reported=20091022,public=20091022,sou...
Keywords: Security
Depends On: 545136 577243
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-03-26 13:35 UTC by Petr Matousek
Modified: 2016-04-26 16:17 UTC (History)
5 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2013-04-10 20:58:14 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0271 normal SHIPPED_LIVE Important: kvm security, bug fix and enhancement update 2010-03-29 13:19:48 UTC
Red Hat Product Errata RHSA-2010:0476 normal SHIPPED_LIVE Important: rhev-hypervisor security, bug fix, and enhancement update 2010-06-22 13:54:04 UTC

Description Petr Matousek 2010-03-26 13:35:31 UTC
A flaw was found in the way the QEMU-KVM handled erroneous data provided
by the guest Linux virtio-net driver. Due deficiency in the implementation of
the TSO (TCP segment offloading), the guest's virtio-net driver transmitted
improper data to the particular QEMU-KVM process on the host, resulting in its
termination. A remote attacker could use this flaw to cause denial of service
(guest crash) by sending certain, specially-crafted data to arbitrary open port
on the target guest system.

A remote attacker could exploit this to crash guests which use virtio
networking on Linux kernels earlier than 2.6.26.

Comment 3 errata-xmlrpc 2010-03-30 07:51:25 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0271 https://rhn.redhat.com/errata/RHSA-2010-0271.html

Comment 7 Yewei Shao 2010-06-17 14:41:14 UTC
Change the bug to verified according to the bug 577243#c7.

Comment 8 Yewei Shao 2010-06-17 14:42:14 UTC
Update the comment #7:

Change the bug to verified according to the bug 577243#c4.

Comment 9 errata-xmlrpc 2010-06-22 13:54:08 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Virtualization for RHEL-5

Via RHSA-2010:0476 https://rhn.redhat.com/errata/RHSA-2010-0476.html


Note You need to log in before you can comment on or make changes to this bug.