The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | third party advisory |
http://xenbits.xen.org/xsa/advisory-180.html | vendor advisory |
https://libvirt.org/news-2015.html | release notes vendor advisory |
http://www.securitytracker.com/id/1035945 | vdb entry third party advisory |
https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=0d968ad715475a1660779bcdd2c5b38ad63db4cf | |
http://www.openwall.com/lists/oss-security/2016/05/24/5 | mailing list |