Fedora Account System
Red Hat Associate
Red Hat Customer
Quick emulator(Qemu) built with the virtio framework is vulnerable to an infinite loop issue. It could occur if the guest was to set the I/O descriptor buffer length to be zero. A privileged user inside guest could use this flaw to potentially crash the Qemu instance on the host resulting in DoS. Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-07/msg06246.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/07/28/4
Acknowledgments: Name: Li Qiang (360.cn Inc.)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1361428]