A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load device tree blob at boot time. It occurs due to device tree size manipulation before buffer allocation, which could overflow a signed int type. A user/process could use this flaw to potentially execute arbitrary code on a host system with privileges of the QEMU process. Upstream patch: --------------- -> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=da885fe1ee8b4589047484bd7fa05a4905b52b17 -> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=065e6298a75164b4347682b63381dbe752c2b156 Reference: ---------- -> https://www.openwall.com/lists/oss-security/2019/03/27/1
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1693117] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1693118]
Acknowledgments: Name: Kurtis Miller (nccgroup.com)
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1175 https://access.redhat.com/errata/RHSA-2019:1175
This issue has been addressed in the following products: Red Hat OpenStack Platform 14.0 (Rocky) Via RHSA-2019:1667 https://access.redhat.com/errata/RHSA-2019:1667
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2019:1723 https://access.redhat.com/errata/RHSA-2019:1723
This issue has been addressed in the following products: Red Hat OpenStack Platform 13.0 (Queens) Via RHSA-2019:1743 https://access.redhat.com/errata/RHSA-2019:1743
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1881 https://access.redhat.com/errata/RHSA-2019:1881
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Red Hat Virtualization Engine 4.2 Red Hat Virtualization Engine 4.3 Via RHSA-2019:1968 https://access.redhat.com/errata/RHSA-2019:1968
This issue has been addressed in the following products: Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2019:2507 https://access.redhat.com/errata/RHSA-2019:2507
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Red Hat Virtualization Engine 4.3 Via RHSA-2019:2553 https://access.redhat.com/errata/RHSA-2019:2553