Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3345

Опубликовано: 05 нояб. 2019
Источник: rocky
Оценка: Low

Описание

Low: virt:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • ntfs-3g: heap-based buffer overflow leads to local root privilege escalation (CVE-2019-9755)

  • QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824)

  • QEMU: qxl: null pointer dereference while releasing spice resources (CVE-2019-12155)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libiscsix86_648.module+el8.7.0+1084+97b81f61libiscsi-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
libiscsi-develx86_648.module+el8.7.0+1084+97b81f61libiscsi-devel-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
libiscsi-utilsx86_648.module+el8.7.0+1084+97b81f61libiscsi-utils-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
netcfx86_6412.module+el8.7.0+1084+97b81f61netcf-0.2.8-12.module+el8.7.0+1084+97b81f61.x86_64.rpm
netcf-develx86_6412.module+el8.7.0+1084+97b81f61netcf-devel-0.2.8-12.module+el8.7.0+1084+97b81f61.x86_64.rpm
netcf-libsx86_6412.module+el8.7.0+1084+97b81f61netcf-libs-0.2.8-12.module+el8.7.0+1084+97b81f61.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 5 лет назад

ELSA-2019-3345: virt:ol security, bug fix, and enhancement update (LOW)

CVSS3: 7.5
ubuntu
около 6 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 3.8
redhat
около 6 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 7.5
nvd
около 6 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 7.5
debian
около 6 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4 ...