Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 598330 (CVE-2016-9101)

Summary: <app-emulation/qemu-2.8.0: net: eepro100 memory leakage at device unplug (CVE-2016-9101)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: minor CC: qemu+disabled
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B4 [glsa cve]
Package list:
Runtime testing required: ---
Bug Depends on: 601824    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2016-10-28 09:54:23 UTC
From ${URL} :

Quick Emulator(Qemu) built with the i8255x (PRO100) NIC emulation support is 
vulnerable to a memory leakage issue. It could occur while unplugging the 
device, and doing so repeatedly would result in leaking host memory affecting, 
other services on the host.

A privileged user inside guest could use this flaw to cause a DoS on the host 
and/or potentially crash the Qemu process on the host.

Upstream patch:


This issue was reported by Li Qiang of Inc.

@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthias Maier gentoo-dev 2016-11-12 17:20:17 UTC
No upstream patch available.

The proposed fix [1] got rejected - it breaks migration capabilities [2].

Comment 2 Thomas Deutschmann gentoo-dev 2017-01-01 19:11:45 UTC
This was fixed via;a=commit;h=2634ab7fe29b3f75d0865b719caf8f310d634aae which is part of v2.8.0 release:

$ git tag --contains 2634ab7fe29b3f75d0865b719caf8f310d634aae

Stabilization will be happen as part of bug 601824.
Comment 3 Thomas Deutschmann gentoo-dev 2017-01-21 22:50:28 UTC
Added to an existing GLSA request.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-01-23 03:02:11 UTC
This issue was resolved and addressed in
 GLSA 201701-49 at
by GLSA coordinator Aaron Bauman (b-man).