Qemu emulator built with VGA emulation with VESA BIOS Extensions(VBE) support is vulnerable to an OOB r/w access issue. It could occur while doing VGA r/w operations via i/o port methods. A privileged guest user could use this flaw to potentially execute arbitrary code, with privileges of the Qemu process on the host. Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg01197.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/05/09/3
Acknowledgments: Name: Wei Xiao (360.cn Marvel Team), Qinghao Tang (360.cn Marvel Team)
*** Bug 1334178 has been marked as a duplicate of this bug. ***
Public via: http://xenbits.xen.org/xsa/advisory-179.html
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1334346]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1334345]
This issue has been addressed in the following products: RHEV-H and Agents for RHEL-7 Via RHSA-2016:0725 https://rhn.redhat.com/errata/RHSA-2016-0725.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:0724 https://rhn.redhat.com/errata/RHSA-2016-0724.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:0997 https://rhn.redhat.com/errata/RHSA-2016-0997.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 Via RHSA-2016:0999 https://rhn.redhat.com/errata/RHSA-2016-0999.html
This issue has been addressed in the following products: Red Hat OpenStack Platform 8.0 (Liberty) Via RHSA-2016:1002 https://rhn.redhat.com/errata/RHSA-2016-1002.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Via RHSA-2016:1001 https://rhn.redhat.com/errata/RHSA-2016-1001.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Via RHSA-2016:1000 https://rhn.redhat.com/errata/RHSA-2016-1000.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Via RHSA-2016:1019 https://rhn.redhat.com/errata/RHSA-2016-1019.html
xen-4.5.3-3.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
qemu-2.4.1-9.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
xen-4.6.1-8.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
qemu-2.3.1-14.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
xen-4.5.3-5.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: RHEV-H and Agents for RHEL-6 Via RHSA-2016:1224 https://access.redhat.com/errata/RHSA-2016:1224
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2016:1943 https://rhn.redhat.com/errata/RHSA-2016-1943.html