Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 957155 - (CVE-2013-2016) CVE-2013-2016 qemu: virtio: out-of-bounds config space access
CVE-2013-2016 qemu: virtio: out-of-bounds config space access
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20130425,repo...
: Security
Depends On: 956953 957161
Blocks: 957189
  Show dependency treegraph
 
Reported: 2013-04-26 09:27 EDT by Petr Matousek
Modified: 2016-04-26 11:38 EDT (History)
26 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-08-24 10:13:48 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Novell 817593 None None None Never
Gentoo 467846 None None None Never

  None (edit)
Description Petr Matousek 2013-04-26 09:27:56 EDT
A flaw was found in the way qemu validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.

References:

https://lists.gnu.org/archive/html/qemu-devel/2013-04/msg05013.html

Proposed upstream patch:

https://lists.gnu.org/archive/html/qemu-devel/2013-04/msg05254.html

Acknowledgements:                                  

This issue was found by Jason Wang of Red Hat.
Comment 1 Petr Matousek 2013-04-26 09:33:56 EDT
Statement:

Not vulnerable.

This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5 and qemu-kvm package as shipped with Red Hat Enterprise Linux 6.
Comment 2 Petr Matousek 2013-04-26 09:35:29 EDT
Created qemu tracking bugs for this issue

Affects: fedora-all [bug 957161]

Note You need to log in before you can comment on or make changes to this bug.