Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2018:2162 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1553402 | issue tracking third party advisory |
https://access.redhat.com/errata/RHSA-2018:1369 | third party advisory vendor advisory |
https://usn.ubuntu.com/3649-1/ | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2018:1416 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/103350 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2018/03/09/1 | mailing list third party advisory patch |
https://lists.nongnu.org/archive/html/qemu-devel/2018-03/msg02174.html | mailing list patch vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html | mailing list release notes third party advisory vendor advisory |