|   | 
| 
 | 
Message-Id: <20160216144628.DD5EE34E018@smtpvbsrv1.mitre.org> Date: Tue, 16 Feb 2016 09:46:28 -0500 (EST) From: cve-assign@...re.org To: ppandit@...hat.com Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, zuozhi.fzz@...baba-inc.com Subject: Re: CVE request Qemu: usb: multiple eof_timers in ohci leads to null pointer dereference -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 > Qemu emulator built with the USB OHCI emulation support is vulnerable to a > null pointer dereference issue. It could occur when OHCI transitions to a > OHCI_USB_OPERATIONAL state, leading to creation of multiple eof timers. A > privileged user inside guest could use this flaw to crash the Qemu process on > the host, resulting in DoS. > > https://lists.gnu.org/archive/html/qemu-devel/2016-02/msg03374.html > https://bugzilla.redhat.com/show_bug.cgi?id=1304794 >> When transitioning an OHCI controller to the OHCI_USB_OPERATIONAL >> state, it creates an eof timer object in 'ohci_bus_start'. >> It does not check if one already exists. This results in memory >> leakage and null dereference issue. Add a check to avoid it. Use CVE-2016-2391. This is not yet available at http://git.qemu.org/?p=qemu.git;a=history;f=hw/usb/hcd-ohci.c but that may be an expected place for a later update. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJWwzU6AAoJEL54rhJi8gl5lwgP/A9qJ0XBRrulTbKeVQ/An+Vd rgu6xMleEk4DlX/V7WP28GYsrMcsL1Eqr6PBozcC2oEDQRuBeHCmym1A2uu8UEcP FAukVUGglNSa7tv7lCJFSHDfiaEAS3BUfQhkVf5FIF7HbTfV+pqtIJXB4QvzrFkJ Y8mrW58rEXWxcTnZANNVhU24i5abvxZACa79wHnhiashR+teQC8JCb4orgMk/1ZQ uni2BFgpLD1ZVsVw/ZGwfK+fhHqMPN0fmjGtyGhxvmooIEreolH5wjcPZMe2zUjv KtcFJ9eK1HocWSso3NYj4EpbInF9KQzENv/cgtKxRhe0Jz5SYk/i2kFN+aV3l/T0 4vwShU644Y44c8wR8yAq17DQXDRA2h5BrBRuSfntTMGdnkF1Zg9m6fqMGu+HFZJs go6+dSDPmVrW8pfcLlW7vtiDK8+iKLHhPMlR//AfrYt+n3Q2wbAc6U+xtjDN6Cwk bb4jIurHR21E/jmvql1fbS4tVwALCZ5cMNk62QMQjBHgWtj6sFRqMPu9DbdE0u4x CNKbhbKsUlpuBBTAjw2h3V96DGZmIqn1V5BlFc6WktwLEAICIQ6Wm97S1pA5nK+2 KT0kPeQDmw4QL9AsuOFWqqJjsT1kxcv45+mD6WVc3GdGE8l3Rb3qpU2ipsG2osui oUKlYtWgzaNVBADmTzbr =9tAj -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.