Bugzilla – Bug 883826
VUL-0: CVE-2014-3471: qemu: use after free triggered via guest
Last modified: 2020-09-23 15:33:40 UTC
Qemu PCIe bus support is vulnerable to a use-after-free flaw. It could occur via guest, when it tries to hotplug/hotunplug devices on the guest. A user able to add & delete Virtio block devices on a guest could use this flaw to crash the Qemu instance resulting in DoS. ----------------- Couldn't figure out which versions are actually affected. Since RHEL6 isn't affected (0.12.1.2) we only need to worry about SLE 12 and openSUSE Upstream fix: https://lists.gnu.org/archive/html/qemu-devel/2014-06/msg05283.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1112271 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3471 http://seclists.org/oss-sec/2014/q2/611 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3471 https://lists.gnu.org/archive/html/qemu-devel/2014-06/msg05283.html
bugbot adjusting priority
All affected code streams have reached their end-of-life.