Описание
ELSA-2026-39311: qemu-kvm security update (LOW)
[10.1.0-17.el9_8.4]
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184527]
- Resolves: RHEL-184527 (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-9.8.z])
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
qemu-guest-agent
10.1.0-17.el9_8.4
qemu-img
10.1.0-17.el9_8.4
qemu-kvm
10.1.0-17.el9_8.4
qemu-kvm-audio-pa
10.1.0-17.el9_8.4
qemu-kvm-block-blkio
10.1.0-17.el9_8.4
qemu-kvm-block-curl
10.1.0-17.el9_8.4
qemu-kvm-block-rbd
10.1.0-17.el9_8.4
qemu-kvm-common
10.1.0-17.el9_8.4
qemu-kvm-core
10.1.0-17.el9_8.4
qemu-kvm-device-display-virtio-gpu
10.1.0-17.el9_8.4
qemu-kvm-device-display-virtio-gpu-pci
10.1.0-17.el9_8.4
qemu-kvm-device-usb-host
10.1.0-17.el9_8.4
qemu-kvm-device-usb-redirect
10.1.0-17.el9_8.4
qemu-kvm-docs
10.1.0-17.el9_8.4
qemu-kvm-tools
10.1.0-17.el9_8.4
qemu-pr-helper
10.1.0-17.el9_8.4
Oracle Linux x86_64
qemu-guest-agent
10.1.0-17.el9_8.4
qemu-img
10.1.0-17.el9_8.4
qemu-kvm
10.1.0-17.el9_8.4
qemu-kvm-audio-pa
10.1.0-17.el9_8.4
qemu-kvm-block-blkio
10.1.0-17.el9_8.4
qemu-kvm-block-curl
10.1.0-17.el9_8.4
qemu-kvm-block-rbd
10.1.0-17.el9_8.4
qemu-kvm-common
10.1.0-17.el9_8.4
qemu-kvm-core
10.1.0-17.el9_8.4
qemu-kvm-device-display-virtio-gpu
10.1.0-17.el9_8.4
qemu-kvm-device-display-virtio-gpu-pci
10.1.0-17.el9_8.4
qemu-kvm-device-display-virtio-vga
10.1.0-17.el9_8.4
qemu-kvm-device-usb-host
10.1.0-17.el9_8.4
qemu-kvm-device-usb-redirect
10.1.0-17.el9_8.4
qemu-kvm-docs
10.1.0-17.el9_8.4
qemu-kvm-tools
10.1.0-17.el9_8.4
qemu-kvm-ui-egl-headless
10.1.0-17.el9_8.4
qemu-kvm-ui-opengl
10.1.0-17.el9_8.4
qemu-pr-helper
10.1.0-17.el9_8.4
Связанные CVE
Связанные уязвимости
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling
A flaw was found in QEMU's virtio-blk device. The issue arises because ...