ELSA-2018-2462

ELSA-2018-2462 - qemu-kvm security and bug fix update

Type:SECURITY
Impact:IMPORTANT
Release Date:2018-08-16

Description


[1.5.3-156.el7_5.5]
- kvm-multiboot-bss_end_addr-can-be-zero.patch [bz#1549824]
- kvm-multiboot-Remove-unused-variables-from-multiboot.c.patch [bz#1549824]
- kvm-multiboot-Use-header-names-when-displaying-fields.patch [bz#1549824]
- kvm-multiboot-fprintf-stderr.-error_report.patch [bz#1549824]
- kvm-multiboot-Reject-kernels-exceeding-the-address-space.patch [bz#1549824]
- kvm-multiboot-Check-validity-of-mh_header_addr.patch [bz#1549824]
- kvm-slirp-remove-mbuf-m_hdr-m_dat-indirection.patch [bz#1586248]
- kvm-slirp-correct-size-computation-while-concatenating-m.patch [bz#1586248]
- Resolves: bz#1549824
(CVE-2018-7550 qemu-kvm: Qemu: i386: multiboot OOB access while loading kernel image [rhel-7.5.z])
- Resolves: bz#1586248
(CVE-2018-11806 qemu-kvm: QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams [rhel-7.5.z])

[1.5.3-156.el7_5.4]
- kvm-target-i386-introduce-kvm_put_one_msr.patch [bz#1596302]
- kvm-apic-fix-2.2-2.1-migration.patch [bz#1596302]
- kvm-x86-lapic-Load-LAPIC-state-at-post_load.patch [bz#1596302]
- kvm-apic-drop-debugging.patch [bz#1596302]
- kvm-apic-set-APIC-base-as-part-of-kvm_apic_put.patch [bz#1596302]
- Resolves: bz#1596302
(Windows 2012 Guest hangs after live migration with RTC clock stopped. [rhel-7.5.z])


Related CVEs


CVE-2018-7550
CVE-2018-11806

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) qemu-kvm-1.5.3-156.el7_5.5.src.rpm27b15e39896c0300d70399928357368fbc643f3924d290a1b0016cdab9290ba0ELBA-2024-12732ol7_x86_64_latest
qemu-kvm-1.5.3-156.el7_5.5.src.rpm27b15e39896c0300d70399928357368fbc643f3924d290a1b0016cdab9290ba0ELBA-2024-12732ol7_x86_64_u5_patch
qemu-img-1.5.3-156.el7_5.5.x86_64.rpmd77bfde83f6f41c7a59c9644c80db7d31c44885129679009df2bf7f6690b15eaELBA-2024-12732ol7_x86_64_latest
qemu-img-1.5.3-156.el7_5.5.x86_64.rpmd77bfde83f6f41c7a59c9644c80db7d31c44885129679009df2bf7f6690b15eaELBA-2024-12732ol7_x86_64_u5_patch
qemu-kvm-1.5.3-156.el7_5.5.x86_64.rpm7282cb25fe6b52319636330d53ca1939d98f9ab14d73bfb3dc00509020a4a317ELBA-2024-12732ol7_x86_64_latest
qemu-kvm-1.5.3-156.el7_5.5.x86_64.rpm7282cb25fe6b52319636330d53ca1939d98f9ab14d73bfb3dc00509020a4a317ELBA-2024-12732ol7_x86_64_u5_patch
qemu-kvm-common-1.5.3-156.el7_5.5.x86_64.rpmd44668d8fd45c4faa694a799e46874e4b4913167945a436ff39c22eb0c246a51ELBA-2022-4639ol7_x86_64_latest
qemu-kvm-common-1.5.3-156.el7_5.5.x86_64.rpmd44668d8fd45c4faa694a799e46874e4b4913167945a436ff39c22eb0c246a51ELBA-2022-4639ol7_x86_64_u5_patch
qemu-kvm-tools-1.5.3-156.el7_5.5.x86_64.rpmfc74ce13e02f50c08dbd4b9b740e9f64b1e8d77d2e4813816cbd8f224aa8fffdELBA-2022-4639ol7_x86_64_latest
qemu-kvm-tools-1.5.3-156.el7_5.5.x86_64.rpmfc74ce13e02f50c08dbd4b9b740e9f64b1e8d77d2e4813816cbd8f224aa8fffdELBA-2022-4639ol7_x86_64_u5_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete