REDHAT-BUG-1444781: Low severity Qemu Qemu vulnerability
Quick Emulator(Qemu) built with the virtio-9p back-end support is vulnerable to a memory leakage issue. It could occur while querying file system extended attributes via 9pfslistxattr() routine.
A privileged user/process inside guest could use this flaw to leak host memory resulting in Dos.
Upstream patch: --------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=4ffcdef4277a91af15a3c09f7d16af072c29f3f2
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/04/25/5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1444781?
The severity of REDHAT-BUG-1444781 is low.
What type of issue does REDHAT-BUG-1444781 describe?
REDHAT-BUG-1444781 describes a memory leakage issue in Qemu.
Who is affected by REDHAT-BUG-1444781?
A privileged user or process inside a guest can be affected by REDHAT-BUG-1444781.
What could an attacker achieve by exploiting REDHAT-BUG-1444781?
An attacker could potentially leak host memory and cause a denial of service (DoS) due to REDHAT-BUG-1444781.
How can I mitigate the risks associated with REDHAT-BUG-1444781?
Mitigating risks for REDHAT-BUG-1444781 involves updating Qemu to the latest version that addresses this vulnerability.