The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/03/02/8 | mailing list |
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=415ab35a441eca767d033a2702223e785b9d5190 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1303106 | |
http://www.securityfocus.com/bid/84028 | vdb entry |
https://security.gentoo.org/glsa/201609-01 | vendor advisory |
https://lists.gnu.org/archive/html/qemu-devel/2016-02/msg06126.html | mailing list vendor advisory |
http://www.ubuntu.com/usn/USN-2974-1 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html | mailing list |
http://lists.nongnu.org/archive/html/qemu-stable/2016-03/msg00064.html | mailing list vendor advisory |