Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:9136

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: qemu-kvm security update

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • QEMU: SR-IOV: improper validation of NumVFs leads to buffer overflow (CVE-2024-26327)

  • QEMU: virtio: DMA reentrancy issue leads to double free vulnerability (CVE-2024-3446)

  • QEMU: Denial of Service via Improper Synchronization in QEMU NBD Server During Socket Closure (CVE-2024-7409)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
qemu-guest-agentx86_6410.el9_5.2qemu-guest-agent-9.0.0-10.el9_5.2.x86_64.rpm
qemu-imgx86_6410.el9_5.2qemu-img-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvmx86_6410.el9_5.2qemu-kvm-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-audio-pax86_6410.el9_5.2qemu-kvm-audio-pa-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-block-blkiox86_6410.el9_5.2qemu-kvm-block-blkio-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-block-curlx86_6410.el9_5.2qemu-kvm-block-curl-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-block-rbdx86_6410.el9_5.2qemu-kvm-block-rbd-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-commonx86_6410.el9_5.2qemu-kvm-common-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-corex86_6410.el9_5.2qemu-kvm-core-9.0.0-10.el9_5.2.x86_64.rpm
qemu-kvm-device-display-virtio-gpux86_6410.el9_5.2qemu-kvm-device-display-virtio-gpu-9.0.0-10.el9_5.2.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 1 года назад

ELSA-2024-9136: qemu-kvm security update (MODERATE)

oracle-oval
около 1 года назад

ELSA-2024-12674: qemu-kvm security update (IMPORTANT)

oracle-oval
около 1 года назад

ELSA-2024-12604: virt:kvm_utils3 security update (IMPORTANT)

CVSS3: 5.3
ubuntu
больше 1 года назад

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.

CVSS3: 5.5
redhat
больше 1 года назад

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.