Quick Emulator(Qemu) built with the PC System Emulator with multiboot feature support is vulnerable to an OOB r/w memory access issue. It could occur due to an integer overflow while loading a kernel image during a guest boot. A user/process could use this flaw to potentially achieve arbitrary code execution on a host. Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2017-09/msg01483.html Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/09/07/2
Acknowledgments: Name: Thomas Garnier (Google.com)
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1489376]
qemu-2.9.1-2.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:3369 https://access.redhat.com/errata/RHSA-2017:3369
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:3368 https://access.redhat.com/errata/RHSA-2017:3368
This issue has been addressed in the following products: Red Hat OpenStack Platform 8.0 (Liberty) Via RHSA-2017:3471 https://access.redhat.com/errata/RHSA-2017:3471
This issue has been addressed in the following products: Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2017:3470 https://access.redhat.com/errata/RHSA-2017:3470
This issue has been addressed in the following products: Red Hat OpenStack Platform 11.0 (Ocata) Via RHSA-2017:3466 https://access.redhat.com/errata/RHSA-2017:3466
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2017:3474 https://access.redhat.com/errata/RHSA-2017:3474
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Via RHSA-2017:3472 https://access.redhat.com/errata/RHSA-2017:3472
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Via RHSA-2017:3473 https://access.redhat.com/errata/RHSA-2017:3473