Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 15.10 Moderate Advisory: QEMU Denial Of Service Risks

ubuntu
Calendar Grey February 3, 2016
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
Several security issues were fixed in QEMU.

Summary

Several security issues were fixed in QEMU.

Software Description:

- qemu: Machine emulator and virtualizer

- qemu-kvm: Machine emulator and virtualizer

Details:

Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An

attacker inside the guest could use this issue to cause QEMU to crash,

resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS

and Ubuntu 15.10. (CVE-2015-7549)

Lian Yihan discovered that QEMU incorrectly handled the VNC server. A

remote attacker could use this issue to cause QEMU to crash, resulting in a

denial of service. (CVE-2015-8504)

Felix Wilhelm discovered a race condition in the Xen paravirtualized

drivers which can cause double fetch vulnerabilities. An attacker in the

paravirtualized guest could exploit this flaw to cause a denial of service

(crash the host) or potentially execute arbitrary code on the host.

(CVE-2015-8550)

Qinghao Tang discovered that QEMU incorrectly handled USB EHCI emu...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  qemu-system                     1:2.3+dfsg-5ubuntu9.2
  qemu-system-aarch64             1:2.3+dfsg-5ubuntu9.2
  qemu-system-arm                 1:2.3+dfsg-5ubuntu9.2
  qemu-system-mips                1:2.3+dfsg-5ubuntu9.2
  qemu-system-misc                1:2.3+dfsg-5ubuntu9.2
  qemu-system-ppc                 1:2.3+dfsg-5ubuntu9.2
  qemu-system-sparc               1:2.3+dfsg-5ubuntu9.2
  qemu-system-x86                 1:2.3+dfsg-5ubuntu9.2

Ubuntu 14.04 LTS:
  qemu-system                     2.0.0+dfsg-2ubuntu1.22
  qemu-system-aarch64             2.0.0+dfsg-2ubuntu1.22
  qemu-system-arm                 2.0.0+dfsg-2ubuntu1.22
  qemu-system-mips                2.0.0+dfsg-2ubuntu1.22
  qemu-system-misc                2.0.0+dfsg-2ubuntu1.22
  qemu-system-ppc                 2.0.0+dfsg-2ubuntu1.22
  qemu-system-sparc               2.0.0+dfsg-2ubuntu1.22
  qemu-system-x86                 2.0.0+dfsg-2ubuntu1.22

Ubuntu 12.04 LTS:
  qemu-kvm                        1.0+noroms-0ubuntu14.27

After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2891-1

CVE-2015-7549, CVE-2015-8504, CVE-2015-8550, CVE-2015-8558,

CVE-2015-8567, CVE-2015-8568, CVE-2015-8613, CVE-2015-8619,

CVE-2015-8666, CVE-2015-8743, CVE-2015-8744, CVE-2015-8745,

CVE-2016-1568, CVE-2016-1714, CVE-2016-1922, CVE-2016-1981,

CVE-2016-2197, CVE-2016-2198

February 03, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.