ELSA-2019-4631

ELSA-2019-4631 - qemu security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2019-05-14

Description


[12:2.9.0-21.el7]
- x86: Add mds feature (Karl Heubaum)
- e1000: Never increment the RX undersize count register (Chris Kenna)
- i386: Add some MSR based features on Cascadelake-Server CPU model (Tao Xu) [Orabug: 29643540]
- i386: Update stepping of Cascadelake-Server (Tao Xu) [Orabug: 29643540]
- kvm: Use KVM_GET_MSR_INDEX_LIST for MSR_IA32_ARCH_CAPABILITIES support (Bandan Das) [Orabug: 29643540]
- x86: define a new MSR based feature word -- FEATURE_WORDS_ARCH_CAPABILITIES (Robert Hoo) [Orabug: 29643540]
- x86: Data structure changes to support MSR based features (Robert Hoo) [Orabug: 29643540]
- kvm: Add support to KVM_GET_MSR_FEATURE_INDEX_LIST and KVM_GET_MSRS system ioctl (Robert Hoo) [Orabug: 29643540]
- i386: Add CPUID bit and feature words for IA32_ARCH_CAPABILITIES MSR (Robert Hoo) [Orabug: 29643540]
- i386: Add new MSR indices for IA32_PRED_CMD and IA32_ARCH_CAPABILITIES (Robert Hoo) [Orabug: 29643540]
- update Linux headers to 4.16-rc5 (Paolo Bonzini) [Orabug: 29643540]
- linux-headers: update (Cornelia Huck) [Orabug: 29643540]
- linux-headers: update to 4.15-rc1 (Eric Auger) [Orabug: 29643540]
- linux-headers: sync against v4.14-rc1 (Alexey Perevalov) [Orabug: 29643540]
- linux header sync against v4.13-rc1 (Christian Borntraeger) [Orabug: 29643540]
- linux-headers: update to 4.13-rc0 (Christian Borntraeger) [Orabug: 29643540]
- parfait: --disable-avx2 no longer needed by rpmbuild (Liam Merwick) [Orabug: 28733157]
- parfait: deal with parfait returning non-zero return value (Liam Merwick) [Orabug: 28733157]
- parfait: use nproc to choose default number of threads (Liam Merwick) [Orabug: 28733157]
- parfait: provide option to upload results (Liam Merwick) [Orabug: 28733157]
- parfait: disable misaligned-access check (Liam Merwick) [Orabug: 28733157]
- parfait: Run static analysis when --with parfait specified (Liam Merwick) [Orabug: 28733157]
- parfait: add buildrpm/parfait-qemu.conf (Liam Merwick) [Orabug: 28733157]
- device_tree.c: Don't use load_image() (Peter Maydell) [Orabug: 29546331] {CVE-2018-20815}
- slirp: check sscanf result when emulating ident (William Bowling) [Orabug: 29501785] {CVE-2019-9824}
- i2c-ddc: fix oob read (Gerd Hoffmann) [Orabug: 29377317] {CVE-2019-3812}


Related CVEs



Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) qemu-2.9.0-21.el7.src.rpm5d668ec2df580fb569be868a893a8f5d4d7d29bafe0a45043e1eede467f5d920ELBA-2023-24511ol7_x86_64_kvm_utils
qemu-2.9.0-21.el7.x86_64.rpmd849376f30443a02347f93f90dff11cde6ef234195ab3a4edc800d91c1bddb79ELBA-2023-24511ol7_x86_64_kvm_utils
qemu-block-gluster-2.9.0-21.el7.x86_64.rpmd271cc41c4c2b2d9752e08133fc4195f65f5515a328098329b778512d28d0abfELBA-2024-12732ol7_x86_64_kvm_utils
qemu-block-iscsi-2.9.0-21.el7.x86_64.rpm2601f4fe953b684703158632c5659f8389f23d30f2e752b28af68037ef856b07ELBA-2024-12732ol7_x86_64_kvm_utils
qemu-block-rbd-2.9.0-21.el7.x86_64.rpma41474c0ef0740b3ed134563f54663931696bf5e22299917e4e23ee3fa9ee5aeELBA-2024-12732ol7_x86_64_kvm_utils
qemu-common-2.9.0-21.el7.x86_64.rpme09d232b0e851277eaa38e489ed20fe1cda8fedb27af5c7b6aec42bea28c49abELBA-2023-24511ol7_x86_64_kvm_utils
qemu-img-2.9.0-21.el7.x86_64.rpm4881a528d725dd448d6c8b57ed1d1c4a99f74701c7c9271bf2e2527c5d6dcf95ELBA-2024-12732ol7_x86_64_kvm_utils
qemu-kvm-2.9.0-21.el7.x86_64.rpm011e589fe51b5869a30834966edda7aeada99cdae938b4f1a2ad1cb08d8d653fELBA-2024-12732ol7_x86_64_kvm_utils
qemu-kvm-core-2.9.0-21.el7.x86_64.rpm75ffa22721c4814d6dd42857d5eeffbfab2ade52eff83cde6956ba208ae3cf72ELBA-2024-12732ol7_x86_64_kvm_utils
qemu-system-x86-2.9.0-21.el7.x86_64.rpm787de20bdcc6b1f41d3981c9a9705a3e8c40721a424351e083ced4d20a19aa27ELBA-2023-24511ol7_x86_64_kvm_utils
qemu-system-x86-core-2.9.0-21.el7.x86_64.rpmf4a1a96385ec40e2006bd1a31c33fd605162bfb7b3dcebf658a19ac7d1b4e31cELBA-2024-12732ol7_x86_64_kvm_utils



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete