Описание
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
Quick Emulator (QEMU) built with the virtio framework is vulnerable to an unbounded memory allocation issue. It was found that a malicious guest user could submit more requests than the virtqueue size permits. Processing a request allocates a VirtQueueElement results in unbounded memory allocation on the host controlled by the guest.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kvm | Affected | ||
Red Hat Enterprise Linux 5 | xen | Will not fix | ||
Red Hat Enterprise Linux 6 | qemu-kvm-rhev | Affected | ||
Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Not affected | ||
Red Hat Enterprise Linux 5 | kvm | Fixed | RHSA-2016:1943 | 27.09.2016 |
Red Hat Enterprise Linux 6 | qemu-kvm | Fixed | RHSA-2016:1585 | 09.08.2016 |
Red Hat Enterprise Linux 7 | qemu-kvm | Fixed | RHSA-2016:1606 | 11.08.2016 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | qemu-kvm-rhev | Fixed | RHSA-2016:1652 | 23.08.2016 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | qemu-kvm-rhev | Fixed | RHSA-2016:1655 | 23.08.2016 |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | qemu-kvm-rhev | Fixed | RHSA-2016:1654 | 23.08.2016 |
Показывать по
Дополнительная информация
Статус:
3.4 Low
CVSS3
2.3 Low
CVSS2
Связанные уязвимости
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local ...
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
3.4 Low
CVSS3
2.3 Low
CVSS2