oss-sec mailing list archives
Fwd: [vs-plain] CVE-2015-5261
From: Huzaifa Sidhpurwala <huzaifas () redhat com>
Date: Tue, 6 Oct 2015 11:20:57 +0530
Making this public as promised on distros list! -------- Forwarded Message -------- Subject: [vs-plain] CVE-2015-5261 Date: Tue, 29 Sep 2015 10:52:43 +0530 From: Huzaifa Sidhpurwala <huzaifas () redhat com> To: distros () vs openwall org Hello Vendors, Frediano Ziglio of Red Hat has found a security flaw in spice related to, host memory access from guest using crafted images. Details as follows: It is possible for a guest issuing QXL commands to host to allow reading and writing host memory in a range of about 16-20gb. The guest can create a surface very large (say 1000000 x 1000000). If width * height overflow the 32 bit and became a small number the host will accept the command and will create the surface. Now guest can copy areas of surfaces to access any area of memory covered by the image. Considering overflows, pixman implementation and image formats (32 bit, top-down or down-top) the range (the guest pass an offset into video memory for the start) the range if about +/- 8gb. We have assigned CVE-2015-5261 to this issue. Reference: https://bugzilla.redhat.com/show_bug.cgi?id=1261889 -- Huzaifa Sidhpurwala / Red Hat Product Security Team
Current thread:
- Fwd: [vs-plain] CVE-2015-5261 Huzaifa Sidhpurwala (Oct 05)