Bug 27879 - qemu several security issues
Summary: qemu several security issues
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Thierry Vignaud
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-12-19 19:43 CET by Zombie Ryushu
Modified: 2021-07-01 18:26 CEST (History)
0 users

See Also:
Source RPM: qemu-4.0.0-2.mga7.src
CVE:
Status comment:


Attachments

Description Zombie Ryushu 2020-12-19 19:43:33 CET
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
Zombie Ryushu 2020-12-19 19:43:44 CET

Status comment: (none) => CVE-2020-27821

Comment 1 Lewis Smith 2020-12-19 20:32:14 CET
This is not a duplicate. Thank you for the alert.

We have qemu-5.2.0-3.mga8.src.rpm in M8.
You look the right target for this (qemu), Thierry.

Assignee: bugsquad => thierry.vignaud
QA Contact: (none) => security

Comment 2 David Walser 2020-12-19 20:38:58 CET
Qemu is vulnerable to a *LOT* more than just this one CVE.  We don't have bugs for them because we don't track Qemu CVEs anymore, because there are just *way* too many of them.

If anyone is interested in tracking them, they should follow the new Qemu security mailing list that was just set up:
https://www.openwall.com/lists/oss-security/2020/12/16/1

Otherwise, probably the best we can do is periodically sync the package with Fedora.

Summary: qemu security vulnerability CVE-2020-27821 => qemu several security issues
Component: RPM Packages => Security

David Walser 2020-12-28 19:02:12 CET

Status comment: CVE-2020-27821 => (none)

Comment 3 David Walser 2021-07-01 18:26:58 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.