Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 16.04 LTS USN-3047-2 Moderate: QEMU Regression Issue Summary

ubuntu
Calendar Grey August 12, 2016
Scroller Ubuntu
Understand the QEMU issue impacting Ubuntu LTS versions and the workaround available. Ensure your system remains safe by applying the most recent patches.
USN-3047-1 introduced a regression in QEMU.

Summary

USN-3047-1 introduced a regression in QEMU.

Software Description:

- qemu: Machine emulator and virtualizer

- qemu-kvm: Machine emulator and virtualizer

Details:

USN-3047-1 fixed vulnerabilities in QEMU. The patch to fix CVE-2016-5403

caused a regression which resulted in save/restore failures when virtio

memory balloon statistics are enabled. This update temporarily reverts the

security fix for CVE-2016-5403 pending further investigation. We apologize

for the inconvenience.

Original advisory details:

Li Qiang discovered that QEMU incorrectly handled 53C9X Fast SCSI

controller emulation. A privileged attacker inside the guest could use this

issue to cause QEMU to crash, resulting in a denial of service, or possibly

execute arbitrary code on the host. In the default installation, when QEMU

is used with libvirt, attackers would be isolated by the libvirt AppArmor

profile. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.

(CVE-2016-443...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  qemu-system                     1:2.5+dfsg-5ubuntu10.4
  qemu-system-aarch64             1:2.5+dfsg-5ubuntu10.4
  qemu-system-arm                 1:2.5+dfsg-5ubuntu10.4
  qemu-system-mips                1:2.5+dfsg-5ubuntu10.4
  qemu-system-misc                1:2.5+dfsg-5ubuntu10.4
  qemu-system-ppc                 1:2.5+dfsg-5ubuntu10.4
  qemu-system-s390x               1:2.5+dfsg-5ubuntu10.4
  qemu-system-sparc               1:2.5+dfsg-5ubuntu10.4
  qemu-system-x86                 1:2.5+dfsg-5ubuntu10.4

Ubuntu 14.04 LTS:
  qemu-system                     2.0.0+dfsg-2ubuntu1.27
  qemu-system-aarch64             2.0.0+dfsg-2ubuntu1.27
  qemu-system-arm                 2.0.0+dfsg-2ubuntu1.27
  qemu-system-mips                2.0.0+dfsg-2ubuntu1.27
  qemu-system-misc                2.0.0+dfsg-2ubuntu1.27
  qemu-system-ppc                 2.0.0+dfsg-2ubuntu1.27
  qemu-system-sparc               2.0.0+dfsg-2ubuntu1.27
  qemu-system-x86                 2.0.0+dfsg-2ubuntu1.27

Ubuntu 12.04 LTS:
  qemu-kvm                        1.0+noroms-0ubuntu14.30

After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3047-2

https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1612089

August 12, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.