Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 744780 - use-after-free in QEMU SCSI target code
use-after-free in QEMU SCSI target code
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: qemu-kvm (Show other bugs)
6.0
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Paolo Bonzini
Virtualization Bugs
:
Depends On:
Blocks: 750914
  Show dependency treegraph
 
Reported: 2011-10-10 08:56 EDT by Paolo Bonzini
Modified: 2013-01-09 19:26 EST (History)
9 users (show)

See Also:
Fixed In Version: qemu-kvm-0.12.1.2-2.202.el6
Doc Type: Bug Fix
Doc Text:
In rare cases, QEMU could handle a SCSI request by using it after its memory had been freed. This could lead to a segmentation fault. SCSI requests are used by QEMU as part of emulating USB mass storage devices.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-12-06 11:05:31 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1531 normal SHIPPED_LIVE Moderate: qemu-kvm security, bug fix, and enhancement update 2011-12-05 20:23:30 EST

  None (edit)
Description Paolo Bonzini 2011-10-10 08:56:16 EDT
Description of problem:
I found a use-after-free in QEMU's SCSI target code.  Upstream it is easily triggered by ejecting a SCSI CD-ROM during anaconda's media test step.  No known reproducer for RHEL6 (we do not have SCSI CD-ROMs), but fixing it is a good idea anyway because it can be triggered by the guest just by cancelling SCSI commands.

Version-Release number of selected component (if applicable):
qemu-kvm-0.12.1.2-2.194.el6
Comment 2 Dor Laor 2011-10-10 13:17:20 EDT
(In reply to comment #0)
> Description of problem:
> I found a use-after-free in QEMU's SCSI target code.  Upstream it is easily
> triggered by ejecting a SCSI CD-ROM during anaconda's media test step.  No
> known reproducer for RHEL6 (we do not have SCSI CD-ROMs), but fixing it is a
> good idea anyway because it can be triggered by the guest just by cancelling
> SCSI commands.
> 
> Version-Release number of selected component (if applicable):
> qemu-kvm-0.12.1.2-2.194.el6

Since we don't support scsi at all for now, how can this be effective? Shouldn't we wait for 6.3?
Comment 3 Paolo Bonzini 2011-10-11 04:16:24 EDT
USB implies SCSI. :(
Comment 4 juzhang 2011-10-11 05:01:10 EDT
> but fixing it is a
> good idea anyway because it can be triggered by the guest just by cancelling
> SCSI commands.
> 
Hi,Paolo

   Would you please provide a efficient way to reproduce this issue?as you mentioned that "can be triggered by the guest just by cancelling
SCSI commands."? please qe detailed steps? thanks
Comment 5 Paolo Bonzini 2011-10-11 06:02:18 EDT
I don't have a reproducer for RHEL6 right now, but I can try.
Comment 11 juzhang 2011-10-27 02:20:45 EDT
(In reply to comment #5)
> I don't have a reproducer for RHEL6 right now, but I can try.
Hi,Paolo

   Would you please tell me do you have any idea to reproduce this issue,thanks
Comment 12 Paolo Bonzini 2011-10-27 03:27:27 EDT
Is it fine to reproduce it with additional patches to QEMU?
Comment 13 juzhang 2011-10-27 03:52:06 EDT
(In reply to comment #12)
> Is it fine to reproduce it with additional patches to QEMU?
Sure,thanks
Comment 15 Eduardo Habkost 2011-10-28 13:59:06 EDT
Moving to ON_QA because Errata Tool did not do it
Comment 17 juzhang 2011-10-31 23:22:02 EDT
> known reproducer for RHEL6 (we do not have SCSI CD-ROMs), but fixing it is a
> good idea anyway because it can be triggered by the guest just by cancelling
> SCSI commands.
Hi,Paolo

Since rhel6 have no scsi-cd,so we can not trigger this issue directly.in rhel6.2,USB implies SCSI.so,our qe will do the following things to verify this issue,it's ok for you?
1.Do usb functional testing.
2.check whether this this patch is applied to rhel6.
Comment 18 juzhang 2011-11-06 21:24:09 EST
Since rhel6 have no scsi-cd,so we can not trigger this issue directly.in
rhel6.2,USB implies SCSI.so,our qe will do the following things to verify this
issue.
Verified this issue with qemu-kvm-0.12.1.2-2.207.el6
1.Do usb functional testing,did find regression issues.
https://tcms.engineering.redhat.com/run/29985/

2.check whether this this patch is applied to rhel6.
#rpm -qa --changelog qemu-kvm | grep  744780 
- kvm-scsi-fix-accounting-of-writes.patch [bz#744780]
- kvm-scsi-disk-bump-SCSIRequest-reference-count-until-aio.patch [bz#744780]
- Resolves: bz#744780
Comment 20 Paolo Bonzini 2011-11-17 12:34:50 EST
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
In rare cases, QEMU could handle a SCSI request by using it after its memory had been freed.  This could lead to a segmentation fault.  SCSI requests are used by QEMU as part of emulating USB mass storage devices.
Comment 21 errata-xmlrpc 2011-12-06 11:05:31 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2011-1531.html

Note You need to log in before you can comment on or make changes to this bug.