Fedora Account System
Red Hat Associate
Red Hat Customer
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes. Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2016-11/msg00019.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/12/05/22
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1402247]
commit 42a8dadc74f8982fc269e54e3c5627b54d9f83d8 Author: Li Qiang <liqiang6-s> Date: Tue Nov 1 02:53:11 2016 -0700 virtio-gpu: fix information leak in getting capset info dispatch