Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3345

Опубликовано: 05 нояб. 2019
Источник: rocky
Оценка: Low

Описание

Low: virt:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • ntfs-3g: heap-based buffer overflow leads to local root privilege escalation (CVE-2019-9755)

  • QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824)

  • QEMU: qxl: null pointer dereference while releasing spice resources (CVE-2019-12155)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libiscsiaarch648.module+el8.7.0+1084+97b81f61libiscsi-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm
libiscsiaarch648.module+el8.4.0+534+4680a14elibiscsi-1.18.0-8.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsiaarch648.module+el8.6.0+847+b490afddlibiscsi-1.18.0-8.module+el8.6.0+847+b490afdd.aarch64.rpm
libiscsi-develaarch648.module+el8.7.0+1084+97b81f61libiscsi-devel-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm
libiscsi-develaarch648.module+el8.4.0+534+4680a14elibiscsi-devel-1.18.0-8.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsi-develaarch648.module+el8.6.0+847+b490afddlibiscsi-devel-1.18.0-8.module+el8.6.0+847+b490afdd.aarch64.rpm
libiscsi-utilsaarch648.module+el8.7.0+1084+97b81f61libiscsi-utils-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm
libiscsi-utilsaarch648.module+el8.4.0+534+4680a14elibiscsi-utils-1.18.0-8.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsi-utilsaarch648.module+el8.6.0+847+b490afddlibiscsi-utils-1.18.0-8.module+el8.6.0+847+b490afdd.aarch64.rpm
netcfaarch6412.module+el8.7.0+1084+97b81f61netcf-0.2.8-12.module+el8.7.0+1084+97b81f61.aarch64.rpm

Показывать по

Связанные уязвимости

oracle-oval
почти 7 лет назад

ELSA-2019-3345: virt:ol security, bug fix, and enhancement update (LOW)

CVSS3: 7.5
ubuntu
больше 7 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 3.8
redhat
больше 7 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 7.5
nvd
больше 7 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS3: 7.5
debian
больше 7 лет назад

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4 ...