Описание
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | released | 0.14.0+noroms-0ubuntu7 |
hardy | DNE | |
lucid | released | 0.12.3+noroms-0ubuntu9.9 |
maverick | released | 0.12.5+noroms-0ubuntu7.5 |
natty | released | 0.14.0+noroms-0ubuntu4.1 |
upstream | needs-triage |
Показывать по
EPSS
7.4 High
CVSS2
Связанные уязвимости
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Managem ...
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
ELSA-2011-0534: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)
EPSS
7.4 High
CVSS2