VENOM

Differences between revisions 21 and 22
Revision 21 as of 2015-05-13 17:09:55
Size: 3371
Editor: tyhicks
Comment:
Revision 22 as of 2015-05-13 17:13:36
Size: 3049
Editor: tyhicks
Comment: Security updates have been published
Deletions are marked like this. Additions are marked like this.
Line 13: Line 13:
A fix for this issue has been [[ http://git.qemu.org/?p=qemu.git;a=commitdiff;h=e907746266721f305d67bc0718795fedee2e824c | committed ]] in the upstream QEMU source code tracker. Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10, and Ubuntu 15.04 are affected. The Ubuntu Security Team is in the process of testing updated packages and security updates will be be available after testing is complete. The Ubuntu Security Team will update this page when updates are available. Once updates are available, we recommend you apply the updates and restart any QEMU virtual machines. A fix for this issue has been [[ http://git.qemu.org/?p=qemu.git;a=commitdiff;h=e907746266721f305d67bc0718795fedee2e824c | committed ]] in the upstream QEMU source code tracker. Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10, and Ubuntu 15.04 are affected. To address the issue, ensure that [[https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.22 | qemu-kvm 1.0+noroms-0ubuntu14.22]] (Ubuntu 12.04 LTS), [[https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.11 | qemu 2.0.0+dfsg-2ubuntu1.11]] (Ubuntu 14.04 LTS), [[https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.6 | qemu 2.1+dfsg-4ubuntu6.6]] (Ubuntu 14.10), [[https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.1 | qemu 1:2.2+dfsg-5expubuntu9.1]] (Ubuntu 15.04) are installed.
Line 15: Line 15:
## To address the issue, ensure that [[https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.22 | qemu-kvm 1.0+noroms-0ubuntu14.22]] (Ubuntu 12.04 LTS), [[https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.11 | qemu 2.0.0+dfsg-2ubuntu1.11 ]] (Ubuntu 14.04 LTS), [[https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.6 | qemu 2.1+dfsg-4ubuntu6.6 ]] (Ubuntu 14.10), [[https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.1 | qemu 1:2.2+dfsg-5expubuntu9.1 ]] (Ubuntu 15.04) are installed. These updates were announced in [[http://www.ubuntu.com/usn/usn-2608-1|USN 2608-1]]. ## These updates were announced in [[http://www.ubuntu.com/usn/usn-2608-1 | USN 2608-1]].
Line 25: Line 25:
## * 2015 May 13: Ubuntu released security updates  * 2015 May 13: Ubuntu released security updates

QEMU buffer overflow in the floppy disk controller (CVE-2015-3456 aka VENOM)

It was discovered that a buffer overflow existed in the virtual floppy disk controller of QEMU. An attacker could use this issue to cause QEMU to crash or execute arbitrary code in the host's QEMU process.

This issue is mitigated in a couple ways on Ubuntu when using libvirt to manage QEMU virtual machines, which includes OpenStack's use of QEMU. The QEMU process in the host environment is owned by a special libvirt-qemu user which helps to limit access to resources in the host environment. Additionally, the QEMU process is confined by an AppArmor profile that significantly lessens the impact of a vulnerability such as VENOM by reducing the host environment's attack surface.

A fix for this issue has been committed in the upstream QEMU source code tracker. Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10, and Ubuntu 15.04 are affected. To address the issue, ensure that qemu-kvm 1.0+noroms-0ubuntu14.22 (Ubuntu 12.04 LTS), qemu 2.0.0+dfsg-2ubuntu1.11 (Ubuntu 14.04 LTS), qemu 2.1+dfsg-4ubuntu6.6 (Ubuntu 14.10), qemu 1:2.2+dfsg-5expubuntu9.1 (Ubuntu 15.04) are installed.

Timeline

  • 2015 Apr 30: The Ubuntu Security Team is notified by CrowdStrike via the linux-distros list, with a pending CRD of 2015-05-13 12:00 UTC

  • 2015 May 13: Issue became public a few hours before the CRD via twitter and reddit with links to CrowdStrike's VENOM page

  • 2015 May 13: CrowdStrike sent a notification email to the oss-security mailing list

  • 2015 May 13: Ubuntu released security updates

Public Cloud Archive updates

  • Ubuntu Cloud Archive Packages: <IN PROGRESS>


CategoryTemplate

SecurityTeam/KnowledgeBase/VENOM (last edited 2015-05-14 06:19:56 by sbeattie)