Описание
Low: virt:rhel security, bug fix, and enhancement update
Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.
Security Fix(es):
-
ntfs-3g: heap-based buffer overflow leads to local root privilege escalation (CVE-2019-9755)
-
QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824)
-
QEMU: qxl: null pointer dereference while releasing spice resources (CVE-2019-12155)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.
Затронутые продукты
Rocky Linux 8
Связанные CVE
Исправления
- Red Hat - 1531543
- Red Hat - 1662272
- Red Hat - 1664463
- Red Hat - 1667249
- Red Hat - 1673010
- Red Hat - 1673396
- Red Hat - 1673401
- Red Hat - 1678515
- Red Hat - 1678979
- Red Hat - 1679483
- Red Hat - 1679966
- Red Hat - 1680231
- Red Hat - 1683681
- Red Hat - 1684383
- Red Hat - 1685151
- Red Hat - 1686895
- Red Hat - 1687541
- Red Hat - 1687596
- Red Hat - 1688062
- Red Hat - 1689297
Связанные уязвимости
ELSA-2019-3345: virt:ol security, bug fix, and enhancement update (LOW)
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4 ...