Bug 1000397 (CVE-2016-7423) - VUL-0: CVE-2016-7423: qemu: scsi: mptsas: OOB access when freeing MPTSASRequest object
Summary: VUL-0: CVE-2016-7423: qemu: scsi: mptsas: OOB access when freeing MPTSASReque...
Status: RESOLVED INVALID
Alias: CVE-2016-7423
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Bruce Rogers
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/172696/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-09-22 10:57 UTC by Victor Pereira
Modified: 2021-09-30 22:35 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2016-09-22 10:57:08 UTC
rh#1376776

Quick emulator(Qemu) built with the LSI SAS1068 Host Bus emulation support,
is vulnerable to an invalid memory access issue. It could occur while
processing scsi io requests in mptsas_process_scsi_io_request.

A privileged user inside guest could use this flaw to crash the Qemu process
instance on the host resulting in DoS.

Upstream patch
--------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03604.html

Reference:
----------
  -> http://www.openwall.com/lists/oss-security/2016/09/16/5

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1376776
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7423
http://seclists.org/oss-sec/2016/q3/531
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7423.html
Comment 1 Swamp Workflow Management 2016-09-22 22:01:33 UTC
bugbot adjusting priority
Comment 2 Johannes Segitz 2016-09-29 15:55:38 UTC
looks to me like we are not affected by this, but please have a look yourself
Comment 3 Bruce Rogers 2017-03-07 01:38:41 UTC
Agreed. We are not affected.