Oval Definition:oval:com.redhat.rhsa:def:20151043
Revision Date:2015-06-03Version:601
Title:RHSA-2015:1043: virtio-win security and bug fix update (Important)
Description:The virtio-win package provides paravirtualized network drivers for most Microsoft Windows operating systems. Paravirtualized drivers are virtualization-aware drivers used by fully virtualized guests running on Red Hat Enterprise Linux. Fully virtualized guests using the paravirtualized drivers gain significantly better I/O performance than fully virtualized guests running without the drivers.

  • It was found that the Windows Virtio NIC driver did not sufficiently sanitize the length of the incoming IP packets, as demonstrated by a packet with IP options present but the overall packet length not being adjusted to reflect the length of those options. A remote attacker able to send a specially crafted IP packet to the guest could use this flaw to crash that guest. (CVE-2015-3215)

    Red Hat would like to thank Google Project Zero for reporting this issue.

    This update also fixes the following bugs:

  • When creating a Windows guest using virtio drivers and direct Logical Unit Number (LUN) access with more than 4 SCSI disks under one virtio-scsi-pci controller, the guest terminated unexpectedly with a stop error, also known as the blue screen of death. This update increases the maximum amount of LUNs per a single virtio-scsi-pci controller has been increased to 254, which prevents the described crash from occurring. (BZ#1210196)

  • The license.txt file in the virtio-win build has been updated to include the correct year number in the copyright information section. (BZ#1210195)

    All virtio-win users are advised to upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-3215
    RHSA-2015:1043-00
    Platform(s):Supplementary for Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • virtio-win is earlier than 0:1.7.4-1.el6_6
  • AND virtio-win is signed with Red Hat redhatrelease2 key
  • AND Package Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • BACK