hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1445621 | third party advisory vdb entry issue tracking |
https://security.gentoo.org/glsa/201706-03 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2017/04/26/5 | third party advisory mailing list |
http://www.securityfocus.com/bid/98015 | third party advisory vdb entry |
https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg04578.html | patch mailing list third party advisory |