Fedora Account System
Red Hat Associate
Red Hat Customer
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes. Upstream patch: --------------- -> http://lists.gnu.org/archive/html/qemu-devel/2016-11/msg00059.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2016/12/06/2
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1402263]
commit 85d9d044471f93c48c5c396f7e217b4ef12f69f8 Author: Li Qiang <liqiang6-s> Date: Tue Nov 1 05:37:57 2016 -0700 virtio-gpu: fix information leak in capset get dispatch