A heap buffer overflow flaw was found in QEMUs Cirrus CLGD 54xx VGA emulators VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.9.0 (excluding) |
Qemu | Ubuntu | devel | * |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | xenial | * |
Qemu | Ubuntu | yakkety | * |
Qemu | Ubuntu | zesty | * |
Xen | Ubuntu | precise | * |
Xen | Ubuntu | trusty | * |
Xen | Ubuntu | upstream | * |
Red Hat Enterprise Linux 6 | RedHat | qemu-kvm-2:0.12.1.2-2.503.el6_9.3 | * |
Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-10:1.5.3-126.el7_3.6 | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3 | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 10.0 (Newton) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 9.0 (Mitaka) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3 | * |
RHEV 3.X Hypervisor and Agents for RHEL-7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |