[Bug 1910941] [NEW] Assertion `addr < cache->len && 2 <= cache->len - addr' in virtio-blk

2021-01-10 Thread Cheol-Woo,Myung
Public bug reported: Hello, Using hypervisor fuzzer, hyfuzz, I found an assertion failure through virtio-blk emulator. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service. This was found in version 5.2.0 (master) ``` qemu-

[Bug 1901532] Re: Assertion failure `mr != NULL' failed through usb-ehci

2020-12-17 Thread Cheol-Woo,Myung
** Changed in: qemu Status: New => Confirmed ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25723 -- You received this bug notification because you are a member of qemu- devel-ml, which is subscribed to QEMU. https://bugs.launchpad.net/bugs/1901532 Title: Assertion f

[Bug 1908513] [NEW] assertion failure in mptsas1068 emulator

2020-12-17 Thread Cheol-Woo,Myung
Public bug reported: Using hypervisor fuzzer, hyfuzz, I found an assertion failure through mptsas1068 emulator. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service. This was found in version 5.2.0 (master) qemu-system-i386:

[Bug 1908515] [NEW] assertion failure in lsi53c810 emulator

2020-12-17 Thread Cheol-Woo,Myung
Public bug reported: Hello, Using hypervisor fuzzer, hyfuzz, I found an assertion failure through lsi53c810 emulator. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service. This was found in version 5.2.0 (master) qemu-syste

[Bug 1907909] [NEW] assertion failure in am53c974

2020-12-12 Thread Cheol-Woo,Myung
Public bug reported: Hello, Using hypervisor fuzzer, hyfuzz, I found an assertion failure through am53c974 emulator. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service. This was found in version 5.2.0 (master) qemu-system

[Bug 1904652] [NEW] Assertion failure in usb-ohci

2020-11-17 Thread Cheol-Woo,Myung
Public bug reported: Hello, Using hypervisor fuzzer, hyfuzz, I found an assertion failure through usb-ohci. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service. This was found in version 5.2.0 (master) ``` Progra

[Bug 1901532] [NEW] Assertion failure `mr != NULL' failed through usb-ehci

2020-10-26 Thread Cheol-Woo,Myung
Public bug reported: Hello, Using hypervisor fuzzer, hyfuzz, I found an assertion failure through usb-ehci. This was found in version 5.0.1 (stable-5.0). qemu-system-i386: src/qemu-repro/exec.c:3581: address_space_unmap: Assertion `mr != NULL' failed. [1]14721 abort src/qemu