Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-0396

Опубликовано: 02 мар. 2017
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2017-0396: qemu-kvm security and bug fix update (IMPORTANT)

[1.5.3-126.el7_3.5]

  • kvm-cirrus-fix-patterncopy-checks.patch [bz#1420490]
  • kvm-Revert-cirrus-allow-zero-source-pitch-in-pattern-fil.patch [bz#1420490]
  • kvm-cirrus-add-blit_is_unsafe-call-to-cirrus_bitblt_cput.patch [bz#1420490]
  • Resolves: bz#1420490 (EMBARGOED CVE-2017-2620 qemu-kvm: Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo [rhel-7.3.z])

[1.5.3-126.el7_3.4]

  • kvm-virtio-blk-Release-s-rq-queue-at-system_reset.patch [bz#1420049]
  • kvm-cirrus_vga-fix-off-by-one-in-blit_region_is_unsafe.patch [bz#1418232]
  • kvm-display-cirrus-check-vga-bits-per-pixel-bpp-value.patch [bz#1418232]
  • kvm-display-cirrus-ignore-source-pitch-value-as-needed-i.patch [bz#1418232]
  • kvm-cirrus-handle-negative-pitch-in-cirrus_invalidate_re.patch [bz#1418232]
  • kvm-cirrus-allow-zero-source-pitch-in-pattern-fill-rops.patch [bz#1418232]
  • kvm-cirrus-fix-blit-address-mask-handling.patch [bz#1418232]
  • kvm-cirrus-fix-oob-access-issue-CVE-2017-2615.patch [bz#1418232]
  • Resolves: bz#1418232 (CVE-2017-2615 qemu-kvm: Qemu: display: cirrus: oob access while doing bitblt copy backward mode [rhel-7.3.z])
  • Resolves: bz#1420049 (system_reset should clear pending request for error (virtio-blk))

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

qemu-img

1.5.3-126.el7_3.5

qemu-kvm

1.5.3-126.el7_3.5

qemu-kvm-common

1.5.3-126.el7_3.5

qemu-kvm-tools

1.5.3-126.el7_3.5

Связанные CVE

Связанные уязвимости

oracle-oval
больше 8 лет назад

ELSA-2017-0454: kvm security update (IMPORTANT)

suse-cvrf
больше 8 лет назад

Security update for xen

suse-cvrf
больше 8 лет назад

Security update for xen

suse-cvrf
больше 8 лет назад

Security update for kvm

suse-cvrf
больше 8 лет назад

Security update for qemu