Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:2135

Опубликовано: 10 мая 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: qemu-kvm security update

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest() (CVE-2023-3019)

  • QEMU: VNC: infinite loop in inflate_buffer() leads to denial of service (CVE-2023-3255)

  • QEMU: improper IDE controller reset can lead to MBR overwrite (CVE-2023-5088)

  • QEMU: VNC: NULL pointer dereference in qemu_clipboard_request() (CVE-2023-6683)

  • QEMU: am53c974: denial of service due to division by zero (CVE-2023-42467)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.4 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
qemu-guest-agentx86_6411.el9_4qemu-guest-agent-8.2.0-11.el9_4.x86_64.rpm
qemu-imgx86_6411.el9_4qemu-img-8.2.0-11.el9_4.x86_64.rpm
qemu-kvmx86_6411.el9_4qemu-kvm-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-audio-pax86_6411.el9_4qemu-kvm-audio-pa-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-block-blkiox86_6411.el9_4qemu-kvm-block-blkio-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-block-curlx86_6411.el9_4qemu-kvm-block-curl-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-block-rbdx86_6411.el9_4qemu-kvm-block-rbd-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-commonx86_6411.el9_4qemu-kvm-common-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-corex86_6411.el9_4qemu-kvm-core-8.2.0-11.el9_4.x86_64.rpm
qemu-kvm-device-display-virtio-gpux86_6411.el9_4qemu-kvm-device-display-virtio-gpu-8.2.0-11.el9_4.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 1 года назад

ELSA-2024-2135: qemu-kvm security update (MODERATE)

oracle-oval
около 1 года назад

ELSA-2024-12407: qemu-kvm security update (MODERATE)

oracle-oval
около 1 года назад

ELSA-2024-12276: virt:kvm_utils3 security update (MODERATE)

oracle-oval
10 месяцев назад

ELSA-2024-12605: virt:kvm_utils2 security update (IMPORTANT)

suse-cvrf
около 1 года назад

Security update for qemu