ALAS2-2023-2191

Related Vulnerabilities: CVE-2023-0330  

There is a vulnerability in the lsi53c895a device which affects the latest version of qemu. The carefully designed PoC can repeatedly trigger DMA writes but does not limit the addresses written to the DMA, resulting in reentrancy issues and eventually overflow. (CVE-2023-0330)

ALAS2-2023-2191


Amazon Linux 2 Security Advisory: ALAS-2023-2191
Advisory Release Date: 2023-08-03 18:10 Pacific
Advisory Updated Date: 2023-08-08 22:02 Pacific
Severity: Medium

Issue Overview:

There is a vulnerability in the lsi53c895a device which affects the latest version of qemu. The carefully designed PoC can repeatedly trigger DMA writes but does not limit the addresses written to the DMA, resulting in reentrancy issues and eventually overflow. (CVE-2023-0330)


Affected Packages:

qemu


Issue Correction:
Run yum update qemu to update your system.

New Packages:
aarch64:
    qemu-3.1.0-8.amzn2.0.13.aarch64
    qemu-common-3.1.0-8.amzn2.0.13.aarch64
    qemu-guest-agent-3.1.0-8.amzn2.0.13.aarch64
    qemu-img-3.1.0-8.amzn2.0.13.aarch64
    ivshmem-tools-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-curl-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-dmg-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-iscsi-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-nfs-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-rbd-3.1.0-8.amzn2.0.13.aarch64
    qemu-block-ssh-3.1.0-8.amzn2.0.13.aarch64
    qemu-audio-alsa-3.1.0-8.amzn2.0.13.aarch64
    qemu-audio-oss-3.1.0-8.amzn2.0.13.aarch64
    qemu-audio-pa-3.1.0-8.amzn2.0.13.aarch64
    qemu-audio-sdl-3.1.0-8.amzn2.0.13.aarch64
    qemu-ui-curses-3.1.0-8.amzn2.0.13.aarch64
    qemu-ui-gtk-3.1.0-8.amzn2.0.13.aarch64
    qemu-ui-sdl-3.1.0-8.amzn2.0.13.aarch64
    qemu-kvm-3.1.0-8.amzn2.0.13.aarch64
    qemu-kvm-core-3.1.0-8.amzn2.0.13.aarch64
    qemu-user-3.1.0-8.amzn2.0.13.aarch64
    qemu-user-binfmt-3.1.0-8.amzn2.0.13.aarch64
    qemu-user-static-3.1.0-8.amzn2.0.13.aarch64
    qemu-system-aarch64-3.1.0-8.amzn2.0.13.aarch64
    qemu-system-aarch64-core-3.1.0-8.amzn2.0.13.aarch64
    qemu-system-x86-3.1.0-8.amzn2.0.13.aarch64
    qemu-system-x86-core-3.1.0-8.amzn2.0.13.aarch64
    qemu-debuginfo-3.1.0-8.amzn2.0.13.aarch64

i686:
    qemu-3.1.0-8.amzn2.0.13.i686
    qemu-common-3.1.0-8.amzn2.0.13.i686
    qemu-guest-agent-3.1.0-8.amzn2.0.13.i686
    qemu-img-3.1.0-8.amzn2.0.13.i686
    ivshmem-tools-3.1.0-8.amzn2.0.13.i686
    qemu-block-curl-3.1.0-8.amzn2.0.13.i686
    qemu-block-dmg-3.1.0-8.amzn2.0.13.i686
    qemu-block-iscsi-3.1.0-8.amzn2.0.13.i686
    qemu-block-nfs-3.1.0-8.amzn2.0.13.i686
    qemu-block-ssh-3.1.0-8.amzn2.0.13.i686
    qemu-audio-alsa-3.1.0-8.amzn2.0.13.i686
    qemu-audio-oss-3.1.0-8.amzn2.0.13.i686
    qemu-audio-pa-3.1.0-8.amzn2.0.13.i686
    qemu-audio-sdl-3.1.0-8.amzn2.0.13.i686
    qemu-ui-curses-3.1.0-8.amzn2.0.13.i686
    qemu-ui-gtk-3.1.0-8.amzn2.0.13.i686
    qemu-ui-sdl-3.1.0-8.amzn2.0.13.i686
    qemu-kvm-3.1.0-8.amzn2.0.13.i686
    qemu-kvm-core-3.1.0-8.amzn2.0.13.i686
    qemu-user-3.1.0-8.amzn2.0.13.i686
    qemu-user-binfmt-3.1.0-8.amzn2.0.13.i686
    qemu-user-static-3.1.0-8.amzn2.0.13.i686
    qemu-system-aarch64-3.1.0-8.amzn2.0.13.i686
    qemu-system-aarch64-core-3.1.0-8.amzn2.0.13.i686
    qemu-system-x86-3.1.0-8.amzn2.0.13.i686
    qemu-system-x86-core-3.1.0-8.amzn2.0.13.i686
    qemu-debuginfo-3.1.0-8.amzn2.0.13.i686

src:
    qemu-3.1.0-8.amzn2.0.13.src

x86_64:
    qemu-3.1.0-8.amzn2.0.13.x86_64
    qemu-common-3.1.0-8.amzn2.0.13.x86_64
    qemu-guest-agent-3.1.0-8.amzn2.0.13.x86_64
    qemu-img-3.1.0-8.amzn2.0.13.x86_64
    ivshmem-tools-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-curl-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-dmg-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-iscsi-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-nfs-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-rbd-3.1.0-8.amzn2.0.13.x86_64
    qemu-block-ssh-3.1.0-8.amzn2.0.13.x86_64
    qemu-audio-alsa-3.1.0-8.amzn2.0.13.x86_64
    qemu-audio-oss-3.1.0-8.amzn2.0.13.x86_64
    qemu-audio-pa-3.1.0-8.amzn2.0.13.x86_64
    qemu-audio-sdl-3.1.0-8.amzn2.0.13.x86_64
    qemu-ui-curses-3.1.0-8.amzn2.0.13.x86_64
    qemu-ui-gtk-3.1.0-8.amzn2.0.13.x86_64
    qemu-ui-sdl-3.1.0-8.amzn2.0.13.x86_64
    qemu-kvm-3.1.0-8.amzn2.0.13.x86_64
    qemu-kvm-core-3.1.0-8.amzn2.0.13.x86_64
    qemu-user-3.1.0-8.amzn2.0.13.x86_64
    qemu-user-binfmt-3.1.0-8.amzn2.0.13.x86_64
    qemu-user-static-3.1.0-8.amzn2.0.13.x86_64
    qemu-system-aarch64-3.1.0-8.amzn2.0.13.x86_64
    qemu-system-aarch64-core-3.1.0-8.amzn2.0.13.x86_64
    qemu-system-x86-3.1.0-8.amzn2.0.13.x86_64
    qemu-system-x86-core-3.1.0-8.amzn2.0.13.x86_64
    qemu-debuginfo-3.1.0-8.amzn2.0.13.x86_64