Bug 1218611 (CVE-2015-3456, VENOM, xsa133) - CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access
Summary: CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-3456, VENOM, xsa133
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1219266 1219267 1219268 1219269 1219270 1219271 1219272 1219333 1219625 1219626 1219854 1219855 1219856 1219858 1219960 1219962 1219969 1220010 1221152 1221153 1222041 1222181 1223300
Blocks: 1218612
TreeView+ depends on / blocked
 
Reported: 2015-05-05 11:56 UTC by Martin Prpič
Modified: 2023-05-12 08:32 UTC (History)
61 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-05-27 13:34:15 UTC
Embargoed:


Attachments (Terms of Use)
A proposed upstream patch. (2.67 KB, patch)
2015-05-07 05:31 UTC, Prasad Pandit
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0998 0 normal SHIPPED_LIVE Important: qemu-kvm security update 2015-05-13 14:55:59 UTC
Red Hat Product Errata RHSA-2015:0999 0 normal SHIPPED_LIVE Important: qemu-kvm security update 2015-05-13 17:36:20 UTC
Red Hat Product Errata RHSA-2015:1000 0 normal SHIPPED_LIVE Important: qemu-kvm-rhev security update 2015-05-13 15:24:42 UTC
Red Hat Product Errata RHSA-2015:1001 0 normal SHIPPED_LIVE Important: qemu-kvm-rhev security update 2015-05-13 15:24:17 UTC
Red Hat Product Errata RHSA-2015:1002 0 normal SHIPPED_LIVE Important: xen security update 2015-05-13 15:22:45 UTC
Red Hat Product Errata RHSA-2015:1003 0 normal SHIPPED_LIVE Important: kvm security update 2015-05-13 15:22:15 UTC
Red Hat Product Errata RHSA-2015:1004 0 normal SHIPPED_LIVE Important: qemu-kvm-rhev security update 2015-05-13 15:18:30 UTC
Red Hat Product Errata RHSA-2015:1011 0 normal SHIPPED_LIVE Important: rhev-hypervisor security update 2015-05-15 23:38:54 UTC
Red Hat Product Errata RHSA-2015:1031 0 normal SHIPPED_LIVE Important: qemu-kvm security update 2015-05-27 15:46:22 UTC

Description Martin Prpič 2015-05-05 11:56:03 UTC
An out-of-bounds memory access flaw was found in the way QEMU's virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the hosting QEMU process.

Acknowledgements:

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting this issue.

Comment 1 Prasad Pandit 2015-05-06 21:22:59 UTC
Statement: 

This issue affects the versions of the kvm and xen packages as shipped with Red Hat Enterprise Linux 5, the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7, and the versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. Future updates for the respective releases will address this flaw.

Comment 14 errata-xmlrpc 2015-05-13 10:56:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2015:0998 https://rhn.redhat.com/errata/RHSA-2015-0998.html

Comment 15 errata-xmlrpc 2015-05-13 11:20:52 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 6
  OpenStack 4 for RHEL 6
  OpenStack 5 for RHEL 7
  OpenStack 6 for RHEL 7

Via RHSA-2015:1004 https://rhn.redhat.com/errata/RHSA-2015-1004.html

Comment 17 errata-xmlrpc 2015-05-13 11:22:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 5

Via RHSA-2015:1003 https://rhn.redhat.com/errata/RHSA-2015-1003.html

Comment 18 errata-xmlrpc 2015-05-13 11:22:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 5

Via RHSA-2015:1002 https://rhn.redhat.com/errata/RHSA-2015-1002.html

Comment 19 errata-xmlrpc 2015-05-13 11:24:28 UTC
This issue has been addressed in the following products:

  RHEV-H and Agents for RHEL-6

Via RHSA-2015:1001 https://rhn.redhat.com/errata/RHSA-2015-1001.html

Comment 20 errata-xmlrpc 2015-05-13 11:24:51 UTC
This issue has been addressed in the following products:

  RHEV-H and Agents for RHEL-7

Via RHSA-2015:1000 https://rhn.redhat.com/errata/RHSA-2015-1000.html

Comment 22 Petr Matousek 2015-05-13 11:47:29 UTC
Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1221153]

Comment 23 Petr Matousek 2015-05-13 11:47:36 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1221152]

Comment 25 errata-xmlrpc 2015-05-13 13:36:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:0999 https://rhn.redhat.com/errata/RHSA-2015-0999.html

Comment 26 Jan ONDREJ 2015-05-13 19:10:31 UTC
I think this affects qemu-2.0.0 from EPEL7 too (not only qemu-1.5 from EL7 base).
I have no access to all depending bugs, so sorry if I missed something.

Comment 27 Petr Matousek 2015-05-15 14:44:15 UTC
Created qemu tracking bugs for this issue:

Affects: epel-7 [bug 1222041]

Comment 28 Petr Matousek 2015-05-15 14:45:17 UTC
(In reply to Jan ONDREJ from comment #26)
> I think this affects qemu-2.0.0 from EPEL7 too (not only qemu-1.5 from EL7
> base).

Correct. It's added now, please see bug 1222041 .

Comment 29 errata-xmlrpc 2015-05-15 19:39:03 UTC
This issue has been addressed in the following products:

  RHEV-H and Agents for RHEL-7
  RHEV-H and Agents for RHEL-6

Via RHSA-2015:1011 https://rhn.redhat.com/errata/RHSA-2015-1011.html

Comment 30 Fedora Update System 2015-05-17 06:38:00 UTC
qemu-2.1.3-7.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 32 Fedora Update System 2015-05-22 17:55:14 UTC
qemu-1.6.2-14.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 33 Fedora Update System 2015-05-26 03:21:12 UTC
xen-4.4.2-4.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 34 Fedora Update System 2015-05-26 03:34:26 UTC
xen-4.3.4-4.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 35 Fedora Update System 2015-05-26 03:41:10 UTC
qemu-2.3.0-4.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 36 Fedora Update System 2015-05-26 03:43:32 UTC
xen-4.5.0-9.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 37 errata-xmlrpc 2015-05-27 11:46:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.5 EUS - Server and Compute Node Only

Via RHSA-2015:1031 https://rhn.redhat.com/errata/RHSA-2015-1031.html


Note You need to log in before you can comment on or make changes to this bug.