QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in mcf_fec_receive. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.7.1 (including) |
Qemu | Qemu | 2.8.0-rc0 (including) | 2.8.0-rc0 (including) |
Qemu | Qemu | 2.8.0-rc1 (including) | 2.8.0-rc1 (including) |
Qemu | Qemu | 2.8.0-rc2 (including) | 2.8.0-rc2 (including) |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | upstream | * |
Qemu | Ubuntu | xenial | * |
Qemu | Ubuntu | yakkety | * |
Qemu-kvm | Ubuntu | precise | * |
Qemu-kvm | Ubuntu | precise/esm | * |
Qemu-kvm | Ubuntu | upstream | * |