Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18772

Опубликовано: 12 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18772: qemu-kvm security update (MODERATE)

[10.1.0-17]

  • kvm-mirror-Fix-missed-dirty-bitmap-writes-during-startup.patch [RHEL-155947 RHEL-155948]
  • kvm-linux-aio-Put-all-parameters-into-qemu_laiocb.patch [RHEL-154174]
  • kvm-linux-aio-Resubmit-tails-of-short-reads-writes.patch [RHEL-154174]
  • kvm-block-io_uring-avoid-potentially-getting-stuck-after.patch [RHEL-154174]
  • kvm-io-uring-Resubmit-tails-of-short-writes.patch [RHEL-154174]
  • Resolves: RHEL-155947 (Mirror job can miss writes during startup, corrupting the copy [rhel-9.8])
  • Resolves: RHEL-155948 (Mirror job can miss writes during startup, corrupting the copy [rhel-9])
  • Resolves: RHEL-154174 (qemu-kvm: disk writes of fewer bytes than requested is a retry condition, not necessarily an indication of ENOSPC [rhel-9.8])

[10.1.0-16]

  • kvm-block-Never-drop-BLOCK_IO_ERROR-with-action-stop-for.patch [RHEL-151679]
  • Resolves: RHEL-151679 ([rhel-9.8] Regression in BLOCK_IO_ERROR event delivery with (w|r)error setting of 'stop' or 'enospc' due to event rate limiting)

[10.1.0-15]

  • kvm-scsi-generalize-scsi_SG_IO_FROM_DEV-to-scsi_SG_IO.patch [RHEL-149396]
  • kvm-scsi-add-error-reporting-to-scsi_SG_IO.patch [RHEL-149396]
  • kvm-scsi-track-SCSI-reservation-state-for-live-migration.patch [RHEL-149396]
  • kvm-scsi-save-load-SCSI-reservation-state.patch [RHEL-149396]
  • kvm-docs-add-SCSI-migrate-pr-documentation.patch [RHEL-149396]
  • Resolves: RHEL-149396 (Migrate SCSI PR state and preempt reservation upon live migration [rhel-9])

[10.1.0-14]

  • kvm-rbd-Run-co-BH-CB-in-the-coroutine-s-AioContext.patch [RHEL-67115]
  • kvm-curl-Fix-coroutine-waking.patch [RHEL-67115]
  • kvm-block-io-Take-reqs_lock-for-tracked_requests.patch [RHEL-67115]
  • kvm-qcow2-Re-initialize-lock-in-invalidate_cache.patch [RHEL-67115]
  • kvm-qcow2-Fix-cache_clean_timer.patch [RHEL-67115]
  • Resolves: RHEL-67115 ([network-storage][rbd][core-dump]installation of guest failed sometimes with multiqueue enabled[rhel9.6])

[10.1.0-13]

  • kvm-vhost-user-make-vhost_set_vring_file-synchronous.patch [RHEL-147422]
  • kvm-hw-s390x-Fix-a-possible-crash-with-passed-through-vi.patch [RHEL-130620]
  • Resolves: RHEL-147422 (virtiofs: processes become stuck in request_wait_answer on virtiofs mounts)
  • Resolves: RHEL-130620 (VM crashes during boot when virtio device is attached through vfio_ccw [rhel-9])

[10.1.0-12]

  • kvm-block-Improve-comments-in-BlockLimits.patch [RHEL-132989]
  • kvm-block-Expose-block-limits-for-images-in-QMP.patch [RHEL-132989]
  • kvm-qemu-img-info-Optionally-show-block-limits.patch [RHEL-132989]
  • kvm-qemu-img-info-Add-cache-mode-option.patch [RHEL-132989]
  • kvm-hw-intc-ioapic-Fix-ACCEL_KERNEL_GSI_IRQFD_POSSIBLE-t.patch [RHEL-140187]
  • kvm-q35-increase-default-tseg-size.patch [RHEL-139057]
  • Resolves: RHEL-132989 (Expose block limits of block nodes in QMP and qemu-img [rhel-9])
  • Resolves: RHEL-140187 (Intel IOMMU VM freezes: 'call_irq_handler: 3.37 No irq handler for vector'[rhel-9.8])
  • Resolves: RHEL-139057 ([qemu, rhel-9] increase default TSEG size)

[10.1.0-11]

  • kvm-block-Fix-BDS-use-after-free-during-shutdown.patch [RHEL-138240]
  • Resolves: RHEL-138240 (QEMU crashes when stopping source VM during live migration [rhel-9])

[10.1.0-10]

  • kvm-monitor-generalize-query-mshv-info-mshv-to-query-acc.patch [RHEL-132193]
  • Resolves: RHEL-132193 ([rhel 9.8]L1VH qemu downstream initial merge RHEL9)

[10.1.0-9]

  • kvm-pcie_sriov-make-pcie_sriov_pf_exit-safe-on-non-SR-IO.patch [RHEL-131144]
  • kvm-accel-Add-Meson-and-config-support-for-MSHV-accelera.patch [RHEL-132193]
  • kvm-target-i386-emulate-Allow-instruction-decoding-from-.patch [RHEL-132193]
  • kvm-target-i386-mshv-Add-x86-decoder-emu-implementation.patch [RHEL-132193]
  • kvm-hw-intc-Generalize-APIC-helper-names-from-kvm_-to-ac.patch [RHEL-132193]
  • kvm-include-hw-hyperv-Add-MSHV-ABI-header-definitions.patch [RHEL-132193]
  • kvm-linux-headers-linux-Add-mshv.h-headers.patch [RHEL-132193]
  • kvm-accel-mshv-Add-accelerator-skeleton.patch [RHEL-132193]
  • kvm-accel-mshv-Register-memory-region-listeners.patch [RHEL-132193]
  • kvm-accel-mshv-Initialize-VM-partition.patch [RHEL-132193]
  • kvm-accel-mshv-Add-vCPU-creation-and-execution-loop.patch [RHEL-132193]
  • kvm-treewide-rename-qemu_wait_io_event-qemu_wait_io_even.patch [RHEL-132193]
  • kvm-accel-mshv-Add-vCPU-signal-handling.patch [RHEL-132193]
  • kvm-target-i386-mshv-Add-CPU-create-and-remove-logic.patch [RHEL-132193]
  • kvm-target-i386-mshv-Implement-mshv_store_regs.patch [RHEL-132193]
  • kvm-target-i386-mshv-Implement-mshv_get_standard_regs.patch [RHEL-132193]
  • kvm-target-i386-mshv-Implement-mshv_get_special_regs.patch [RHEL-132193]
  • kvm-target-i386-mshv-Implement-mshv_arch_put_registers.patch [RHEL-132193]
  • kvm-target-i386-mshv-Set-local-interrupt-controller-stat.patch [RHEL-132193]
  • kvm-target-i386-mshv-Register-CPUID-entries-with-MSHV.patch [RHEL-132193]
  • kvm-target-i386-mshv-Register-MSRs-with-MSHV.patch [RHEL-132193]
  • kvm-target-i386-mshv-Integrate-x86-instruction-decoder-e.patch [RHEL-132193]
  • kvm-target-i386-mshv-Write-MSRs-to-the-hypervisor.patch [RHEL-132193]
  • kvm-target-i386-mshv-Implement-mshv_vcpu_run.patch [RHEL-132193]
  • kvm-accel-mshv-Handle-overlapping-mem-mappings.patch [RHEL-132193]
  • kvm-qapi-accel-Allow-to-query-mshv-capabilities.patch [RHEL-132193]
  • kvm-target-i386-mshv-Use-preallocated-page-for-hvcall.patch [RHEL-132193]
  • kvm-docs-Add-mshv-to-documentation.patch [RHEL-132193]
  • kvm-MAINTAINERS-Add-maintainers-for-mshv-accelerator.patch [RHEL-132193]
  • kvm-accel-mshv-initialize-thread-name.patch [RHEL-132193]
  • kvm-accel-mshv-use-return-value-of-handle_pio_str_read.patch [RHEL-132193]
  • Resolves: RHEL-131144 (qemu crash after hot-unplug disk from the multifunction enabled bus [RHEL.9.8])
  • Resolves: RHEL-132193 ([rhel 9.8]L1VH qemu downstream initial merge RHEL9)

[10.1.0-8]

  • kvm-file-posix-Handle-suspended-dm-multipath-better-for-.patch [RHEL-133303]
  • Resolves: RHEL-133303 (The VM hit io error when do S3-PR integration on the pass-through failover multipath device [rhel-9])

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

qemu-guest-agent

10.1.0-17.el9_8

qemu-img

10.1.0-17.el9_8

qemu-kvm

10.1.0-17.el9_8

qemu-kvm-audio-pa

10.1.0-17.el9_8

qemu-kvm-block-blkio

10.1.0-17.el9_8

qemu-kvm-block-curl

10.1.0-17.el9_8

qemu-kvm-block-rbd

10.1.0-17.el9_8

qemu-kvm-common

10.1.0-17.el9_8

qemu-kvm-core

10.1.0-17.el9_8

qemu-kvm-device-display-virtio-gpu

10.1.0-17.el9_8

qemu-kvm-device-display-virtio-gpu-pci

10.1.0-17.el9_8

qemu-kvm-device-usb-host

10.1.0-17.el9_8

qemu-kvm-device-usb-redirect

10.1.0-17.el9_8

qemu-kvm-docs

10.1.0-17.el9_8

qemu-kvm-tools

10.1.0-17.el9_8

qemu-pr-helper

10.1.0-17.el9_8

Oracle Linux x86_64

qemu-guest-agent

10.1.0-17.el9_8

qemu-img

10.1.0-17.el9_8

qemu-kvm

10.1.0-17.el9_8

qemu-kvm-audio-pa

10.1.0-17.el9_8

qemu-kvm-block-blkio

10.1.0-17.el9_8

qemu-kvm-block-curl

10.1.0-17.el9_8

qemu-kvm-block-rbd

10.1.0-17.el9_8

qemu-kvm-common

10.1.0-17.el9_8

qemu-kvm-core

10.1.0-17.el9_8

qemu-kvm-device-display-virtio-gpu

10.1.0-17.el9_8

qemu-kvm-device-display-virtio-gpu-pci

10.1.0-17.el9_8

qemu-kvm-device-display-virtio-vga

10.1.0-17.el9_8

qemu-kvm-device-usb-host

10.1.0-17.el9_8

qemu-kvm-device-usb-redirect

10.1.0-17.el9_8

qemu-kvm-docs

10.1.0-17.el9_8

qemu-kvm-tools

10.1.0-17.el9_8

qemu-kvm-ui-egl-headless

10.1.0-17.el9_8

qemu-kvm-ui-opengl

10.1.0-17.el9_8

qemu-pr-helper

10.1.0-17.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
redhat
10 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
msrc
10 месяцев назад

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
debian
10 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...