summary refs log tree commit diff stats
path: root/gitlab/issues/target_missing/host_missing/accel_missing/2528.toml
diff options
context:
space:
mode:
authorChristian Krinitsin <mail@krinitsin.com>2025-05-21 21:21:26 +0200
committerChristian Krinitsin <mail@krinitsin.com>2025-05-21 21:21:26 +0200
commit4b927bc37359dec23f67d3427fc982945f24f404 (patch)
tree245449ef9146942dc7fffd0235b48b7e70a00bf2 /gitlab/issues/target_missing/host_missing/accel_missing/2528.toml
parentaa8bd79cec7bf6790ddb01d156c2ef2201abbaab (diff)
downloademulator-bug-study-4b927bc37359dec23f67d3427fc982945f24f404.tar.gz
emulator-bug-study-4b927bc37359dec23f67d3427fc982945f24f404.zip
add gitlab issues in toml format
Diffstat (limited to 'gitlab/issues/target_missing/host_missing/accel_missing/2528.toml')
-rw-r--r--gitlab/issues/target_missing/host_missing/accel_missing/2528.toml17
1 files changed, 17 insertions, 0 deletions
diff --git a/gitlab/issues/target_missing/host_missing/accel_missing/2528.toml b/gitlab/issues/target_missing/host_missing/accel_missing/2528.toml
new file mode 100644
index 00000000..6240d91c
--- /dev/null
+++ b/gitlab/issues/target_missing/host_missing/accel_missing/2528.toml
@@ -0,0 +1,17 @@
+id = 2528
+title = "nbd: CVE-2024-7409 fix is incomplete"
+state = "closed"
+created_at = "2024-08-22T14:43:30.468Z"
+closed_at = "2024-09-02T09:38:17.906Z"
+labels = ["Stable::to backport", "Storage", "kind::Bug", "workflow::Patch available"]
+url = "https://gitlab.com/qemu-project/qemu/-/issues/2528"
+host-os = "- OS/kernel version:"
+host-arch = "- QEMU flavor:"
+qemu-version = "- QEMU command line:"
+guest-os = "- OS/kernel version:"
+guest-arch = "## Description of problem"
+description = """Patch will hit list soon, but opening issue here since if this misses 9.1, we would need to allocate a second CVE for having an incomplete fix (a remaining use-after-free) in the code originally proposed for CVE-2024-7409."""
+reproduce = """1. stress test of attempting repeated 'qemu-nbd --list' in parallel with repeated 'nbd-server-start/nbd-server-stop' loops in a qemu process revealed a use-after-free SEGV of nbd_server->listener
+2.
+3."""
+additional = """"""