Summary: | <app-emulation/qemu-kvm-0.14.1-r2: acpi_piix4: missing hotplug check during device removal (CVE-2011-1751) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Stefan Behte (RETIRED) <craig> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | cardoe, jmbsvicetto, lu_zero, tommy |
Priority: | Highest | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Deadline: | 2011-05-18 |
Description
Stefan Behte (RETIRED)
![]() ![]() Please provide an updated ebuild: a bump is needed for #364889 anyways and I think that issue is nearly as bad as this one. This one is embargoed for about three weeks, so I think it would be cool if you could bump #364889 for 0.13.x (looks like an easy patch to me) and have 0.14.x with patch for this issue ready in three weeks? As I have several machines running KVM, I'd be glad to help out: you can catch me IRC or via mail. Public now. I don't see this in upstream's repo. Any idea where it can be found? Fixed in app-emulation/qemu-kvm-0.14.1, which is now in the tree. The target stable version will be qemu-kvm-0.14.1-r1 When can this go stable? added it to existing glsa request. Stable now, removing dependency. Added to pending GLSA request. CVE-2011-1751 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1751): The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers." This issue was resolved and addressed in GLSA 201210-04 at http://security.gentoo.org/glsa/glsa-201210-04.xml by GLSA coordinator Stefan Behte (craig). |