SB2017022603 - Fedora 24 update for xen



SB2017022603 - Fedora 24 update for xen

Published: February 26, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017022603
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2017-2620)

The vulnerability allows a remote user to gain access to potentially sensitive information.

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.


Remediation

Install update from vendor's website.