Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <alpine.LFD.2.20.1706051704190.26243@wniryva>
Date: Mon, 5 Jun 2017 17:06:51 +0530 (IST)
From: P J P <ppandit@...hat.com>
To: oss security list <oss-security@...ts.openwall.com>
cc: Li Qiang <liqiang6-s@....cn>
Subject: CVE-2017-9375 Qemu: usb: xhci infinite recursive call via
 xhci_kick_ep

   Hello,

Quick emulator(Qemu) built with the USB xHCI controller emulator support is 
vulnerable to an infinite recursive call loop issue. It could occur while 
processing control transfer descriptors' sequence in xhci_kick_epctx.

A privileged user inside guest could use this flaw to crash the Qemu process 
resulting in DoS.

Upstream patch:
---------------
   -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=96d87bdda3919bb16f754b3d3fd1227e1f38f13c

Reference:
----------
   -> https://bugzilla.redhat.com/show_bug.cgi?id=1458744

This issue was reported by Li Qiang Qihoo 360 Gear Team.

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.