Bug 1000346 (CVE-2016-7422) - VUL-0: CVE-2016-7422: qemu: virtio: null pointer dereference in virtqueu_map_desc
Summary: VUL-0: CVE-2016-7422: qemu: virtio: null pointer dereference in virtqueu_map_...
Status: RESOLVED FIXED
Alias: CVE-2016-7422
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Bruce Rogers
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/172697/
Whiteboard: CVSSv2:RedHat:CVE-2016-7422:2.3:(AV:A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-09-22 07:21 UTC by Victor Pereira
Modified: 2017-08-03 08:27 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2016-09-22 07:21:37 UTC
rh#1376755

Quick emulator(Qemu) built with the virtio framework is vulnerable to a null
pointer dereference flaw. It could occur if the guest was to set the I/O
descriptor buffer length to a large value.

A privileged user inside guest could use this flaw to crash the Qemu instance
on the host resulting in DoS.

Upstream fix:
-------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03546.html


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1376755
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7422
http://seclists.org/oss-sec/2016/q3/530
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7422.html
Comment 1 Swamp Workflow Management 2016-09-22 22:00:30 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2016-11-22 18:05:18 UTC
SUSE-SU-2016:2879-1: An update that solves 21 vulnerabilities and has 6 fixes is now available.

Category: security (moderate)
Bug References: 1000345,1000346,1001151,1002116,1002549,1002550,1002557,1003612,1003613,1003878,1003893,1003894,1004702,1004706,1004707,1005353,1005374,1006536,1006538,1007263,1007391,1007493,1007494,1007495,1007769,1008148,998516
CVE References: CVE-2016-7161,CVE-2016-7170,CVE-2016-7422,CVE-2016-7466,CVE-2016-7907,CVE-2016-7908,CVE-2016-7909,CVE-2016-7994,CVE-2016-7995,CVE-2016-8576,CVE-2016-8577,CVE-2016-8578,CVE-2016-8667,CVE-2016-8668,CVE-2016-8669,CVE-2016-8909,CVE-2016-8910,CVE-2016-9101,CVE-2016-9104,CVE-2016-9105,CVE-2016-9106
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    qemu-2.6.2-31.2
SUSE Linux Enterprise Server 12-SP2 (src):    qemu-2.6.2-31.2
SUSE Linux Enterprise Desktop 12-SP2 (src):    qemu-2.6.2-31.2
Comment 3 Swamp Workflow Management 2016-12-22 14:12:05 UTC
openSUSE-SU-2016:3237-1: An update that solves 21 vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 1000345,1000346,1001151,1002116,1002549,1002550,1002557,1003612,1003613,1003878,1003893,1003894,1004702,1004706,1004707,1005353,1005374,1006536,1006538,1007391,1007493,1007494,1007495,1007769,1008148,998516
CVE References: CVE-2016-7161,CVE-2016-7170,CVE-2016-7422,CVE-2016-7466,CVE-2016-7907,CVE-2016-7908,CVE-2016-7909,CVE-2016-7994,CVE-2016-7995,CVE-2016-8576,CVE-2016-8577,CVE-2016-8578,CVE-2016-8667,CVE-2016-8668,CVE-2016-8669,CVE-2016-8909,CVE-2016-8910,CVE-2016-9101,CVE-2016-9104,CVE-2016-9105,CVE-2016-9106
Sources used:
openSUSE Leap 42.2 (src):    qemu-2.6.2-23.1, qemu-linux-user-2.6.2-23.1, qemu-testsuite-2.6.2-23.1
Comment 4 Bruce Rogers 2017-03-07 22:53:50 UTC
Fixed.