From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:43003) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bQ9lg-0006r5-CP for qemu-devel@nongnu.org; Thu, 21 Jul 2016 04:55:45 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bQ9lc-00071m-Ki for qemu-devel@nongnu.org; Thu, 21 Jul 2016 04:55:44 -0400 Received: from mx1.redhat.com ([209.132.183.28]:51847) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bQ9lc-00071g-FF for qemu-devel@nongnu.org; Thu, 21 Jul 2016 04:55:40 -0400 Date: Thu, 21 Jul 2016 09:55:35 +0100 From: "Daniel P. Berrange" Message-ID: <20160721085535.GA13528@redhat.com> Reply-To: "Daniel P. Berrange" References: <8E78D212B8C25246BE4CE7EA0E645FE53D7ED8@SZXEMI504-MBS.china.huawei.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <8E78D212B8C25246BE4CE7EA0E645FE53D7ED8@SZXEMI504-MBS.china.huawei.com> Content-Transfer-Encoding: quoted-printable Subject: Re: [Qemu-devel] oss-security - CVE-2014-3672 libvirt: DoS via excessive logging List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "Xulei (Stone)" Cc: "Ian.Jackson" , qemu-devel On Thu, Jul 21, 2016 at 02:24:43AM +0000, Xulei (Stone) wrote: > Hi, >=20 > A CVE=EF=BC=88CVE-2014-3672=EF=BC=89 vulnerability was reported in Xen.= =20 > I want to know how to reproduce this CVE and whether the qemu-kvm was a= ffected ? >=20 > Hyperlink: https://web.nvd.nist.gov/view/vuln/detail?vulnId=3DCVE-2014-= 3672 > Hyperlink: http://www.openwall.com/lists/oss-security/2016/05/24/5 Yes, QEMU is affected, but we did not fix it at the QEMU layer. Instead libvirt has introduced a virtlogd daemon to handle all writing of data to files. So QEMU now merely writes a pipe FD, and virtlogd takes care of file rotation. Regards, Daniel --=20 |: http://berrange.com -o- http://www.flickr.com/photos/dberrange= / :| |: http://libvirt.org -o- http://virt-manager.or= g :| |: http://autobuild.org -o- http://search.cpan.org/~danberr= / :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vn= c :|