A NULL pointer dereference issue was found in the Floopy disk emulator of QEMU. It could occur while processing read/write ioport commands, if the selected Floopy drive is not initialised with a block device. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Name: Gaoning Pan (Zhejiang University & Ant Security Light-Year Lab)
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1919532]
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1919533]
This issue affects the version of the qemu-kvm package shipped with Red Hat Enterprise Linux 5, 6, 7 and 8. Future qemu-kvm package updates for Red Hat Enterprise Linux 7 and 8 may address this issue.
This has been rated as having Low security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 & 6. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.