oss-sec mailing list archives

CVE-2017-9375 Qemu: usb: xhci infinite recursive call via xhci_kick_ep


From: P J P <ppandit () redhat com>
Date: Mon, 5 Jun 2017 17:06:51 +0530 (IST)

  Hello,

Quick emulator(Qemu) built with the USB xHCI controller emulator support is vulnerable to an infinite recursive call loop issue. It could occur while processing control transfer descriptors' sequence in xhci_kick_epctx.

A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS.

Upstream patch:
---------------
  -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=96d87bdda3919bb16f754b3d3fd1227e1f38f13c

Reference:
----------
  -> https://bugzilla.redhat.com/show_bug.cgi?id=1458744

This issue was reported by Li Qiang Qihoo 360 Gear Team.

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F


Current thread: