Hide Forgot
Quick Emulator(Qemu) built with the VMWARE PVSCSI paravirtual SCSI bus emulation support is vulnerable to an OOB access and/or infinite loop issue. It could occur while processing SCSI commands 'PVSCSI_CMD_SETUP_RINGS'. A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS. Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg00050.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/09/06/2
Acknowledgments: Name: Li Qiang (360.cn Inc.), Victor V (360.cn Inc.)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1373463]
commit 7f61f4690dd153be98900a2a508b88989e692753 Author: Prasad J Pandit <pjp> Date: Wed Aug 31 12:19:29 2016 +0530 vmw_pvscsi: check page count while initialising descriptor rings