QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html | third party advisory mailing list |
https://security.gentoo.org/glsa/201701-49 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2016/12/02/3 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/12/02/8 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1400829 | issue tracking third party advisory |
http://www.securityfocus.com/bid/94638 | vdb entry third party advisory |
https://lists.gnu.org/archive/html/qemu-devel/2016-11/msg05324.html | mailing list patch vendor advisory |