REDHAT-BUG-1958955: Low severity Qemu vhost-user-gpu vulnerability
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU. The flaw exists in virglcmdgetcapsetinfo() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
Patch series: https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg04536.html
Memory disclosure in virglcmdgetcapsetinfo() in virgl.c: https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg04539.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1958955?
The severity of REDHAT-BUG-1958955 is characterized as an information disclosure vulnerability.
How do I fix REDHAT-BUG-1958955?
To fix REDHAT-BUG-1958955, you should update to the latest version of QEMU vhost-user-gpu that contains the necessary patches.
What software is affected by REDHAT-BUG-1958955?
The affected software by REDHAT-BUG-1958955 is QEMU vhost-user-gpu.
What type of vulnerability is REDHAT-BUG-1958955?
REDHAT-BUG-1958955 is an information disclosure vulnerability resulting from reading uninitialized memory.
Who can exploit REDHAT-BUG-1958955?
A malicious guest within a QEMU virtualized environment can exploit REDHAT-BUG-1958955.