Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
| Software | From | Fixed in |
|---|---|---|
| qemu / qemu | - | 2.8.1.1.x |
| suse / linux_enterprise_server | 12-ltss | 12-ltss.x |
| suse / linux_enterprise_software_development_kit | 12-sp1 | 12-sp1.x |
| suse / linux_enterprise_server | 12-sp1 | 12-sp1.x |
| suse / linux_enterprise_desktop | 12-sp1 | 12-sp1.x |
| suse / linux_enterprise_server_for_sap | 12 | 12.x |