Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:5821

Опубликовано: 02 авг. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow (CVE-2021-4206)

  • QEMU: QXL: double fetch in qxl_cursor() can lead to heap buffer overflow (CVE-2021-4207)

  • QEMU: virtio-net: map leaking on error during receive (CVE-2022-26353)

  • QEMU: vhost-vsock: missing virtqueue detach on error can lead to memory leak (CVE-2022-26354)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Rocky Linux 9.0 guest with vsock device migration failed from Rocky Linux 9.0 > Rocky Linux 8.6 (BZ#2071103)

  • Fail to rebuild the reference count tables of qcow2 image on host block devices (e.g. LVs) (BZ#2072242)

  • Remove upstream-only devices from the qemu-kvm binary (BZ#2077928)

  • When doing a cpu-baseline between skylake and cascadelake, cascadelake is selected as baseline. (BZ#2084030)

  • Virt-v2v can't convert Rocky Linux8.6 guest from VMware on Rocky Linux8.6 (BZ#2093415)

Enhancement(s):

  • Allow memory prealloc from multiple threads (BZ#2075569)

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
hivexx86_6423.module+el8.7.0+1084+97b81f61hivex-1.3.18-23.module+el8.7.0+1084+97b81f61.x86_64.rpm
hivex-develx86_6423.module+el8.7.0+1084+97b81f61hivex-devel-1.3.18-23.module+el8.7.0+1084+97b81f61.x86_64.rpm
libguestfs-winsupportx86_641.module+el8.7.0+1084+97b81f61libguestfs-winsupport-8.6-1.module+el8.7.0+1084+97b81f61.x86_64.rpm
libiscsix86_648.module+el8.7.0+1084+97b81f61libiscsi-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
libiscsi-develx86_648.module+el8.7.0+1084+97b81f61libiscsi-devel-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
libiscsi-utilsx86_648.module+el8.7.0+1084+97b81f61libiscsi-utils-1.18.0-8.module+el8.7.0+1084+97b81f61.x86_64.rpm
libnbdx86_645.module+el8.7.0+1084+97b81f61libnbd-1.6.0-5.module+el8.7.0+1084+97b81f61.x86_64.rpm
libnbd-bash-completionnoarch5.module+el8.7.0+1084+97b81f61libnbd-bash-completion-1.6.0-5.module+el8.7.0+1084+97b81f61.noarch.rpm
libnbd-develx86_645.module+el8.7.0+1084+97b81f61libnbd-devel-1.6.0-5.module+el8.7.0+1084+97b81f61.x86_64.rpm
libvirt-dbusx86_642.module+el8.7.0+1084+97b81f61libvirt-dbus-1.3.0-2.module+el8.7.0+1084+97b81f61.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
почти 3 года назад

Security update for qemu

oracle-oval
почти 3 года назад

ELSA-2022-5821: virt:ol and virt-devel:ol security, bug fix, and enhancement update (MODERATE)

suse-cvrf
почти 3 года назад

Security update for qemu

oracle-oval
больше 2 лет назад

ELSA-2022-9869: qemu-kvm security update (IMPORTANT)

oracle-oval
больше 2 лет назад

ELSA-2022-9862: kvm_utils2 security update (IMPORTANT)