A buffer overflow flaw was found in the way e1000 emulated device driver of QEMU, a FAST! processor emulator, processed received large e1000 packets, when the SBP and LPE flags were disabled. If the underlying network was configured to allow large (jumbo) packets, a remote attacker could use this flaw to cause relevant guest in question to crash (DoS) or, potentially, the attacker could use this flaw to execute arbitrary code on the guest system with the kernel level privilege. References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696051 [2] http://www.openwall.com/lists/oss-security/2012/12/19/9 [3] http://thread.gmane.org/gmane.comp.emulators.qemu/182666 [4] http://www.openwall.com/lists/oss-security/2013/01/17/12 Relevant upstream patches: [5] http://git.qemu.org/?p=qemu.git;a=commitdiff;h=b0d9ffcd0251161c7c92f94804dcf599dfa3edeb http://git.qemu.org/?p=qemu.git;a=commitdiff;h=2c0331f4f7d241995452b99afaf0aab00493334a
This issue affects the versions of the qemu package, as shipped with Fedora release of 16 and 17. Please schedule an update. -- This issue (probably [*]) affects the version of the qemu package, as shipped with Fedora EPEL 5. Please schedule an update. [*] Saying probably above, since in Fedora EPEL 5 version e1000_receive() routine is declared as returning void in comparison with more recent versions. Therefore not definitely sure the deficiency would be present on this version too. Needs further investigation by someone more familiar with the code. P.S.: Feel free to close the upcoming epel-5 bug (if you realise this isn't an issue for Fedora EPEL 5 version). Thank you, Jan.
Created qemu tracking bugs for this issue Affects: fedora-all [bug 889304] Affects: epel-5 [bug 889305]
The CVE identifier of CVE-2012-6075 has been assigned to this issue: http://www.openwall.com/lists/oss-security/2012/12/30/1
qemu-1.0.1-3.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
qemu-1.2.2-2.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
qemu-0.15.1-9.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
Created xen tracking bugs for this issue Affects: fedora-all [bug 910845]
Statement: (none)
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0599 https://rhn.redhat.com/errata/RHSA-2013-0599.html
This issue has been addressed in following products: RHEV-H and Agents for RHEL-6 Via RHSA-2013:0610 https://rhn.redhat.com/errata/RHSA-2013-0610.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0608 https://rhn.redhat.com/errata/RHSA-2013-0608.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0609 https://rhn.redhat.com/errata/RHSA-2013-0609.html
This issue has been addressed in following products: OpenStack Folsom for RHEL 6 Via RHSA-2013:0639 https://rhn.redhat.com/errata/RHSA-2013-0639.html
This issue has been addressed in following products: RHEV-H and Agents for RHEL-6 Via RHSA-2013:0636 https://rhn.redhat.com/errata/RHSA-2013-0636.html