Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: 2010-51: Qemu: Denial of Service
Posted by Benjamin D. Thomas
A vulnerability has been fixed in Qemu, which could be exploited by attackers to cause a denial of service.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-51 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-04-20
Severity: 4
Type: Remote
------------------------------------------------------------------------
Summary
======
A vulnerability has been fixed in Qemu, which could be exploited by
attackers to cause a denial of service.
Description
==========
CVE-2010-0741:
The virtio_net_bad_features function in hw/virtio-net.c in the
virtio-net driver in the Linux kernel before 2.6.26, when used on a
guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote
attackers to cause a denial of service (guest OS crash, and an
associated qemu-kvm process exit) by sending a large amount of network
traffic to a TCP port on the guest OS, related to a virtio-net whitelist
that includes an improper implementation of TCP Segment Offloading
(TSO).
Affected packages:
Pardus 2009:
qemu, all before 0.10.5-18-6
Resolution
=========
There are update(s) for qemu. You can update them via Package Manager or
with a single command from console:
pisi up qemu
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id661
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0741
* https://bugzilla.redhat.com/show_bug.cgi?idW7218
------------------------------------------------------------------------