Fedora Account System
Red Hat Associate
Red Hat Customer
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is vulnerable to an out of bounds memory access issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to crash the Qemu process instance on a host, resulting in DoS. Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-12/msg01903.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/12/20/1
Acknowledgments: Name: Hongzhenhao Qinghao Tang (360.cn Marvel Team)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1406368]
*** Bug 1343131 has been marked as a duplicate of this bug. ***
commit abd7f08b2353f43274b785db8c7224f082ef4d31 Author: Prasad J Pandit <pjp> Date: Wed Dec 14 12:31:56 2016 +0530 display: virtio-gpu-3d: check virgl capabilities max_size