Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon,  3 Oct 2016 10:25:26 -0400 (EDT)
From: cve-assign@...re.org
To: ppandit@...hat.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, liqiang6-s@....cn
Subject: Re: CVE Request Qemu: net: pcnet: infinite loop in pcnet_rdra_addr

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> Quick Emulator(Qemu) built with the AMD PC-Net II emulator support is
> vulnerable to an infinite loop issue. It could occur while receiving packets
> via pcnet_receive().
> 
> A privileged user/process inside guest could use this issue to crash the Qemu
> process on the host leading to DoS.
> 
> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg07942.html

Use CVE-2016-7909.

This is not yet available at
http://git.qemu.org/?p=qemu.git;a=history;f=hw/net/pcnet.c but
that may be an expected place for a later update.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJX8mkOAAoJEHb/MwWLVhi2JRgP/0R6RXhk6Rx/TmowN+McLxwo
yEuTpDJH+ne/x8E0sos7b9jllE9IKT15shKIp+IiM+djZuLO7h8aezt1FIU+2We8
OTIN1PnHm0G8eR3F26Pd3LdcwmGu7umk0EZ+rl5liYtUq8UzLA6pOwp9/YmLO3wz
6Df0CDCdctImfy5AhSUuzERLrAFIq29DRtUupsjwQyTawC3e+OfLmgCsmILGy+U5
Kb550wAuD7owYGMcGdDvaBaGg20kA73lz1XkXo1JvhxlhW41n9fcnr8IZZ/wFIEm
wNlI8otT4R0YlSbi6lREHtH4XY8t0syUzjANcXyQVmdsq8kKVLGJpCaoPtiyzBkJ
9JKkcyBQxO6DMvCVlvZnowEIRlNAS0d+lVx5Dz+BItA6PZn1g2pv7vfqVdP6uINR
b1vXcE4d1P5g89cM/YVt0f6PaCTU03N/IYnE+aSvgtgfOpDYOAr4/6k7f5vhdGvL
rhcnr5l8wFXVXW7bUcjaFYeLoGMZ6o2PFHNmx7cJY8ia8f5G24+pCWduCL/raq30
mjfkTzozorVIIuNnBCduk5rTk6YIamGRK/6Ix/jaEXrNjBDRtet5Q7nVJkDFUwAS
M1mgfUYDUmxSv87r8nUnvJtj9uVFLBHknZWpjoJ16OTpKwSn7HWrDs6fR6q22rb7
7FsvrZnifI3TIUn0t9Nz
=eytu
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.