The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201611-11 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2016/10/24/5 | third party advisory mailing list |
https://access.redhat.com/errata/RHSA-2017:2392 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html | mailing list third party advisory vendor advisory |
http://www.securityfocus.com/bid/93844 | vdb entry third party advisory |
https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg05495.html | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/10/24/2 | mailing list third party advisory patch |
https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html | third party advisory mailing list |
https://access.redhat.com/errata/RHSA-2017:2408 | third party advisory vendor advisory |