MDVSA-2015:210: qemu

Updated qemu packages fix security vulnerabilities:

A denial of service flaw was found in the way QEMU handled malformed
Physical Region Descriptor Table (PRDT) data sent to the host’s IDE
and/or AHCI controller emulation. A privileged guest user could use
this flaw to crash the system (rhbz#1204919).

It was found that the QEMU’s websocket frame decoder processed incoming
frames without limiting resources used to process the header and the
payload. An attacker able to access a guest’s VNC console could use
this flaw to trigger a denial of service on the host by exhausting
all available memory and CPU (CVE-2015-1779).

Leave a Reply