REDHAT-BUG-1429432: Low severity Qemu Qemu vulnerability
Quick Emulator built with the USB OHCI Emulation support is vulnerable to an infinite loop issue. It could occur while processing an endpoint list descriptor in ohciserviceedlist().
A guest user/process could use this flaw to crash Qemu process resulting in DoS.
Upstream patch: --------------- -> http://git.qemu-project.org/?p=qemu.git;a=commitdiff;h=95ed56939eb2eaa4e2f349fe6dcd13ca4edfd8fb
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/03/06/6
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1429432?
The severity of REDHAT-BUG-1429432 is rated as low.
How do I fix REDHAT-BUG-1429432?
To fix REDHAT-BUG-1429432, you need to apply the recommended patches from the Qemu upstream version.
What is the impact of REDHAT-BUG-1429432?
REDHAT-BUG-1429432 can lead to a denial of service (DoS) by crashing the Qemu process.
Who is affected by REDHAT-BUG-1429432?
Users and processes running guests on Qemu that have USB OHCI Emulation support are affected by REDHAT-BUG-1429432.
When was REDHAT-BUG-1429432 published?
REDHAT-BUG-1429432 was published on March 6, 2017.