REDHAT-BUG-1418342: Low severity Qemu Qemu vulnerability
Quick Emulator(Qemu) built with the MegaRAID SAS 8708EM2 Host Bus Adapter emulation support is vulnerable to a memory leakage issue. It could occur while processing MegaRAID Firmware Interface(MFI) command in 'megasashandledcmd' routine.
A privileged user inside guest could use this flaw to leak host memory resulting DoS issue.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=765a707000e838c30b18d712fe6cb3dd8e0435f3
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/02/01/19
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1418342?
The severity of REDHAT-BUG-1418342 is classified as low.
How do I fix REDHAT-BUG-1418342?
To mitigate REDHAT-BUG-1418342, you should update QEMU to the latest version that addresses this vulnerability.
What software does REDHAT-BUG-1418342 affect?
REDHAT-BUG-1418342 affects the Quick Emulator, commonly known as QEMU.
What type of issue is REDHAT-BUG-1418342?
REDHAT-BUG-1418342 is a memory leakage issue occurring during the processing of MegaRAID firmware commands.
Who is affected by REDHAT-BUG-1418342?
A privileged user inside the guest can exploit REDHAT-BUG-1418342 to leak sensitive information.