First published: Wed Feb 01 2017(Updated: )
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is vulnerable to a host memory leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_RESOURCE_UNREF' command. A guest user/process could use this flaw to leak host memory resulting in DoS. Upstream patch: --------------- -> <a href="https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg04615.html">https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg04615.html</a> Reference: ---------- -> <a href="http://www.openwall.com/lists/oss-security/2017/02/01/21">http://www.openwall.com/lists/oss-security/2017/02/01/21</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <=2.8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.