Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7472

Опубликовано: 08 нояб. 2022
Источник: rocky
Оценка: Low

Описание

Low: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0). (BZ#2066828)

Security Fix(es):

  • QEMU: fdc: heap buffer overflow in DMA read data transfers (CVE-2021-3507)

  • libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service (CVE-2022-0897)

  • libguestfs: Buffer overflow in get_keys leads to DoS (CVE-2022-2211)

  • swtpm: Unchecked header size indicator against expected size (CVE-2022-23645)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
hivexx86_6423.module+el8.7.0+1084+97b81f61hivex-1.3.18-23.module+el8.7.0+1084+97b81f61.x86_64.rpm
hivex-develx86_6423.module+el8.7.0+1084+97b81f61hivex-devel-1.3.18-23.module+el8.7.0+1084+97b81f61.x86_64.rpm
libguestfsx86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-appliancex86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-appliance-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-bash-completionnoarch9.module+el8.7.0+1084+97b81f61.rockylibguestfs-bash-completion-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.noarch.rpm
libguestfs-develx86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-devel-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-gfs2x86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-gfs2-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-gobjectx86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-gobject-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-gobject-develx86_649.module+el8.7.0+1084+97b81f61.rockylibguestfs-gobject-devel-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.x86_64.rpm
libguestfs-inspect-iconsnoarch9.module+el8.7.0+1084+97b81f61.rockylibguestfs-inspect-icons-1.44.0-9.module+el8.7.0+1084+97b81f61.rocky.noarch.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2022-7472: virt:ol and virt-devel:ol security, bug fix, and enhancement update (LOW)

CVSS3: 6.1
ubuntu
больше 4 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 4.6
redhat
больше 4 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
nvd
больше 4 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
debian
больше 4 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU u ...