Oval Definition:oval:com.redhat.rhsa:def:20150869
Revision Date:2015-04-22Version:636
Title:RHSA-2015:0869: kvm security update (Important)
Description:KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for the standard Red Hat Enterprise Linux kernel.

  • It was found that KVM's Write to Model Specific Register (WRMSR) instruction emulation would write non-canonical values passed in by the guest to certain MSRs in the host's context. A privileged guest user could use this flaw to crash the host. (CVE-2014-3610)

  • A race condition flaw was found in the way the Linux kernel's KVM subsystem handled PIT (Programmable Interval Timer) emulation. A guest user who has access to the PIT I/O ports could use this flaw to crash the host. (CVE-2014-3611)

    Red Hat would like to thank Lars Bull of Google and Nadav Amit for reporting the CVE-2014-3610 issue, and Lars Bull of Google for reporting the CVE-2014-3611 issue.

    All kvm users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. Note: The procedure in the Solution section must be performed before this update will take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-3610
    CVE-2014-3611
    RHSA-2015:0869
    RHSA-2015:0869-00
    RHSA-2015:0869-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • kmod-kvm is earlier than 0:83-270.el5_11
  • AND kmod-kvm is signed with Red Hat redhatrelease2 key
  • kmod-kvm-debug is earlier than 0:83-270.el5_11
  • AND kmod-kvm-debug is signed with Red Hat redhatrelease2 key
  • kvm is earlier than 0:83-270.el5_11
  • AND kvm is signed with Red Hat redhatrelease2 key
  • kvm-qemu-img is earlier than 0:83-270.el5_11
  • AND kvm-qemu-img is signed with Red Hat redhatrelease2 key
  • kvm-tools is earlier than 0:83-270.el5_11
  • AND kvm-tools is signed with Red Hat redhatrelease2 key
  • BACK