Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 598330 (CVE-2016-9101) - <app-emulation/qemu-2.8.0: net: eepro100 memory leakage at device unplug (CVE-2016-9101)
Summary: <app-emulation/qemu-2.8.0: net: eepro100 memory leakage at device unplug (CVE...
Status: RESOLVED FIXED
Alias: CVE-2016-9101
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [glsa cve]
Keywords:
Depends on: CVE-2016-9907
Blocks:
  Show dependency tree
 
Reported: 2016-10-28 09:54 UTC by Agostino Sarubbo
Modified: 2017-01-23 03:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-10-28 09:54:23 UTC
From ${URL} :

Quick Emulator(Qemu) built with the i8255x (PRO100) NIC emulation support is 
vulnerable to a memory leakage issue. It could occur while unplugging the 
device, and doing so repeatedly would result in leaking host memory affecting, 
other services on the host.

A privileged user inside guest could use this flaw to cause a DoS on the host 
and/or potentially crash the Qemu process on the host.

Upstream patch:
---------------
   -> https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg03024.html

Reference:
----------
   -> https://bugzilla.redhat.com/show_bug.cgi?id=1389538

This issue was reported by Li Qiang of 360.cn Inc.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthias Maier gentoo-dev 2016-11-12 17:20:17 UTC
No upstream patch available.

The proposed fix [1] got rejected - it breaks migration capabilities [2].

[1] https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg03024.html
[2] https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg03592.html
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-01 19:11:45 UTC
This was fixed via http://git.qemu.org/?p=qemu.git;a=commit;h=2634ab7fe29b3f75d0865b719caf8f310d634aae which is part of v2.8.0 release:

$ git tag --contains 2634ab7fe29b3f75d0865b719caf8f310d634aae
v2.8.0


Stabilization will be happen as part of bug 601824.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-21 22:50:28 UTC
Added to an existing GLSA request.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-01-23 03:02:11 UTC
This issue was resolved and addressed in
 GLSA 201701-49 at https://security.gentoo.org/glsa/201701-49
by GLSA coordinator Aaron Bauman (b-man).