2016-10-07
ALT-BU-2016-3037-1
Branch c7 update bulletin.
Closed vulnerabilities
Published: 2016-04-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-2858
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
References:
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=60253ed1e6ec6d8e5ef2efe7bf755f475dce9956
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=60253ed1e6ec6d8e5ef2efe7bf755f475dce9956
- [oss-security] 20160304 CVE request Qemu: rng-random: arbitrary stack based allocation leading to corruption
- [oss-security] 20160304 CVE request Qemu: rng-random: arbitrary stack based allocation leading to corruption
- [oss-security] 20160306 Re: CVE request Qemu: rng-random: arbitrary stack based allocation leading to corruption
- [oss-security] 20160306 Re: CVE request Qemu: rng-random: arbitrary stack based allocation leading to corruption
- 84134
- 84134
- USN-2974-1
- USN-2974-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1314676
- https://bugzilla.redhat.com/show_bug.cgi?id=1314676
- [debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update
- [debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update
- GLSA-201604-01
- GLSA-201604-01