ELSA-2021-9104

ELSA-2021-9104 - qemu security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2021-03-12

Description


[15:4.2.1-5.el7]
- qemu.spec: use --tls-priority=NORMAL for OL7 (Elena Ufimtseva)
- hostmem: fix default 'prealloc-threads' count (Mark Kanda) [Orabug: 32472127]
- hostmem: introduce 'prealloc-threads' property (Igor Mammedov)
- qom: introduce object_register_sugar_prop (Paolo Bonzini)
- migration/multifd: Do error_free after migrate_set_error to avoid memleaks (Pan Nengyuan)
- multifd/tls: fix memoryleak of the QIOChannelSocket object when cancelling migration (Chuan Zheng)
- migration/multifd: fix hangup with TLS-Multifd due to blocking handshake (Chuan Zheng)
- migration/tls: add trace points for multifd-tls (Chuan Zheng)
- migration/tls: add support for multifd tls-handshake (Chuan Zheng)
- migration/tls: extract cleanup function for common-use (Chuan Zheng)
- migration/multifd: fix memleaks in multifd_new_send_channel_async (Pan Nengyuan)
- migration/multifd: fix nullptr access in multifd_send_terminate_threads (Zhimin Feng)
- migration/tls: add tls_hostname into MultiFDSendParams (Chuan Zheng)
- migration/tls: extract migration_tls_client_create for common-use (Chuan Zheng)
- migration/tls: save hostname into MigrationState (Chuan Zheng)
- tests/qtest: add a test case for pvpanic-pci (Mihai Carabas)
- pvpanic : update pvpanic spec document (Mihai Carabas)
- hw/misc/pvpanic: add PCI interface support (Mihai Carabas)
- hw/misc/pvpanic: split-out generic and bus dependent code (Mihai Carabas)
- 9pfs: Fully restart unreclaim loop (CVE-2021-20181) (Greg Kurz) [Orabug: 32441198] {CVE-2021-20181}
- ide: atapi: check logical block address and read size (CVE-2020-29443) (Prasad J Pandit) [Orabug: 32393835] {CVE-2020-29443}
- Document CVE-2019-20808 as fixed (Mark Kanda) [Orabug: 32339196] {CVE-2019-20808}
- block/iscsi:fix heap-buffer-overflow in iscsi_aio_ioctl_cb (Chen Qun) [Orabug: 32339207] {CVE-2020-11947}
- net: remove an assert call in eth_get_gso_type (Prasad J Pandit) [Orabug: 32102583] {CVE-2020-27617}
- nvdimm: honor -object memory-backend-file, readonly=on option (Stefan Hajnoczi) [Orabug: 32265408]
- hostmem-file: add readonly=on|off option (Stefan Hajnoczi) [Orabug: 32265408]
- memory: add readonly support to memory_region_init_ram_from_file() (Stefan Hajnoczi) [Orabug: 32265408]


Related CVEs


CVE-2020-11947
CVE-2020-29443
CVE-2020-27617
CVE-2019-20808
CVE-2021-20181

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) qemu-4.2.1-5.el7.src.rpm9e067fcc7cbd376c9352ae8f2637f1d5ELBA-2021-9161
qemu-4.2.1-5.el7.aarch64.rpme7eb334983cc6420c2f6c64b6af707b3ELBA-2021-9161
qemu-block-gluster-4.2.1-5.el7.aarch64.rpm48a8dc36d1bd62af351921ae40574059ELBA-2021-9161
qemu-block-iscsi-4.2.1-5.el7.aarch64.rpm350ddb61b78dc51771d1052e66acb6d0ELBA-2021-9161
qemu-block-rbd-4.2.1-5.el7.aarch64.rpm1fd401858e11e8e3ce9a3d86ae7da5c8ELBA-2021-9161
qemu-common-4.2.1-5.el7.aarch64.rpm3217bb1a1d5cf4f0a3634c02e0c07953ELBA-2021-9161
qemu-img-4.2.1-5.el7.aarch64.rpm6e8a4eece04f47d4db8fe83eb05d20b0ELBA-2021-9161
qemu-kvm-4.2.1-5.el7.aarch64.rpmde228baa723ea6e7fd15c36fbb532459ELBA-2021-9161
qemu-kvm-core-4.2.1-5.el7.aarch64.rpm91f6a19e4e4f308d06d839580d9add17ELBA-2021-9161
Oracle Linux 7 (x86_64) qemu-4.2.1-5.el7.src.rpm9e067fcc7cbd376c9352ae8f2637f1d5ELBA-2021-9161
qemu-4.2.1-5.el7.x86_64.rpm31c9ae5a23d555f9bf31d948130f0d6aELBA-2021-9161
qemu-block-gluster-4.2.1-5.el7.x86_64.rpmc2e6101ab21f31b8b9c23620b844ace5ELBA-2021-9161
qemu-block-iscsi-4.2.1-5.el7.x86_64.rpm6a8dd7e3bc1a49e07427908d426a3504ELBA-2021-9161
qemu-block-rbd-4.2.1-5.el7.x86_64.rpm7a635193010d1d0195889f4e093caf10ELBA-2021-9161
qemu-common-4.2.1-5.el7.x86_64.rpmb1aa34496fe0abf0e9e677197b40e528ELBA-2021-9161
qemu-img-4.2.1-5.el7.x86_64.rpmd5706a963f96753b2a5a8c778250c451ELBA-2021-9161
qemu-kvm-4.2.1-5.el7.x86_64.rpm2fdafe657430b6f73e4ed1904b03a9eaELBA-2021-9161
qemu-kvm-core-4.2.1-5.el7.x86_64.rpme6e8f14eb05b99018f9bdad3a1a34dbfELBA-2021-9161
qemu-system-x86-4.2.1-5.el7.x86_64.rpm7c693e281cf8252459297274ded2fb8aELBA-2021-9161
qemu-system-x86-core-4.2.1-5.el7.x86_64.rpm294c56f0bd47c046e28df30126329cd7ELBA-2021-9161



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete