Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-4198

Опубликовано: 15 авг. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-4198: qemu security update (IMPORTANT)

[12:2.9.0-11.1.el7]

  • i386: Define the Virt SSBD MSR and handling of it (CVE-2018-3639) (Konrad Rzeszutek Wilk) [Orabug: 28110449] {CVE-2018-3639}
  • i386: define the AMD 'virt-ssbd' CPUID feature bit (CVE-2018-3639) (Konrad Rzeszutek Wilk) [Orabug: 28110449] {CVE-2018-3639}
  • i386: define the 'ssbd' CPUID feature bit (CVE-2018-3639) (Daniel P. Berrange) [Orabug: 28110449] {CVE-2018-3639}

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

qemu

2.9.0-11.1.el7

qemu-block-gluster

2.9.0-11.1.el7

qemu-block-iscsi

2.9.0-11.1.el7

qemu-block-rbd

2.9.0-11.1.el7

qemu-common

2.9.0-11.1.el7

qemu-img

2.9.0-11.1.el7

qemu-kvm

2.9.0-11.1.el7

qemu-kvm-core

2.9.0-11.1.el7

qemu-system-x86

2.9.0-11.1.el7

qemu-system-x86-core

2.9.0-11.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS3: 5.6
redhat
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS3: 5.5
nvd
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS3: 5.5
debian
около 7 лет назад

Systems with microprocessors utilizing speculative execution and specu ...

suse-cvrf
почти 7 лет назад

Security update for libvirt