Prasad J Pandit, Red Hat Product Security Team, reports:
Qemu emulator built with the NE2000 NIC emulation support is
vulnerable to an infinite loop issue. It could occur when receiving
packets over the network.
A privileged user inside guest could use this flaw to crash the
Qemu instance resulting in DoS.
Qemu emulator built with the NE2000 NIC emulation support is
vulnerable to a heap buffer overflow issue. It could occur when
receiving packets over the network.
A privileged user inside guest could use this flaw to crash the
Qemu instance or potentially execute arbitrary code on the host.