Описание
ELSA-2015-0867: qemu-kvm security and bug fix update (IMPORTANT)
[0.12.1.2-2.448.el6_6.2]
- kvm-cirrus-fix-blit-region-check.patch [bz#1170571]
- kvm-cirrus-don-t-overflow-CirrusVGAState-cirrus_bltbuf.patch [bz#1170571]
- Resolves: bz#1170571 (CVE-2014-8106 qemu-kvm: qemu: cirrus: insufficient blit region checks [rhel-6.6.z])
[0.12.1.2-2.448.el6_6.1]
- kvm-net-Forbid-dealing-with-packets-when-VM-is-not-run_2.patch [bz#970103]
- kvm-virtio-net-drop-assert-on-vm-stop.patch [bz#970103]
- kvm-migration-set-speed-to-maximum-during-last-stage_2.patch [bz#970103]
- kvm-migration-only-call-append-when-there-is-something_2.patch [bz#970103]
- kvm-migration-Only-call-memmove-when-there-is-anything-t.patch [bz#970103]
- kvm-migration-remove-not-needed-ram_save_remaining-fun_2.patch [bz#970103]
- kvm-migration-move-bandwidth-calculation-to-inside-sta_2.patch [bz#970103]
- kvm-migration-Don-t-calculate-bandwidth-when-last-cycl_2.patch [bz#970103]
- kvm-buffered_flush-return-errors.patch [bz#970103]
- kvm-bandwidth_limit-standarize-in-size_t.patch [bz#970103]
- kvm-fix-bz-1196970.patch [bz#1196970]
- Resolves: bz#1196970 (Migrate status is failed after migrate_cancel.)
- Resolves: bz#970103 (Downtime during live migration of busy VM is much higher than migration_downtime in vdsm.conf)
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
qemu-guest-agent
0.12.1.2-2.448.el6_6.2
qemu-img
0.12.1.2-2.448.el6_6.2
qemu-kvm
0.12.1.2-2.448.el6_6.2
qemu-kvm-tools
0.12.1.2-2.448.el6_6.2
Oracle Linux i686
qemu-guest-agent
0.12.1.2-2.448.el6_6.2
Связанные CVE
Связанные уязвимости
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirr ...
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.