Bug 1327206 (CVE-2016-7907) - CVE-2016-7907 Qemu: net: inifinte loop in imx_fec_do_tx() function
Summary: CVE-2016-7907 Qemu: net: inifinte loop in imx_fec_do_tx() function
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2016-7907
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1381182 1381183
Blocks: 1326713
TreeView+ depends on / blocked
 
Reported: 2016-04-14 12:52 UTC by Adam Mariš
Modified: 2021-02-17 04:03 UTC (History)
43 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-16 10:24:29 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2016-04-14 12:52:48 UTC
Quick Emulator(Qemu) built with the i.MX Fast Ethernet Controller emulator 
support is vulnerable to an infinite loop issue. It could occur while processing
packets on the transmit queue in 'imx_fec_do_tx'.

A privileged user/process inside guest could use this issue to crash the Qemu process on the host leading to DoS.

Upstream patch:
---------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg00380.html

Reference:
----------
  -> http://seclists.org/oss-sec/2016/q4/10

Comment 1 Adam Mariš 2016-04-14 12:53:09 UTC
Acknowledgments:

Name: Li Qiang (Qihoo 360 Inc.)

Comment 4 Prasad Pandit 2016-10-03 10:50:50 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1381182]

Comment 5 Andrej Nemec 2016-10-04 08:05:38 UTC
CVE assignment:

http://seclists.org/oss-sec/2016/q4/10


Note You need to log in before you can comment on or make changes to this bug.