Oval Definition:oval:com.redhat.rhsa:def:20170454
Revision Date:2017-03-07Version:635
Title:RHSA-2017:0454: kvm security update (Important)
Description:KVM (for Kernel-based Virtual Machine) is a full virtualization solution for Linux on x86 hardware. Using KVM, one can run multiple virtual machines running unmodified Linux or Windows images. Each virtual machine has private virtualized hardware: a network card, disk, graphics adapter, etc.

Security Fix(es):

  • Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host. (CVE-2017-2615)

  • Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process. (CVE-2017-2620)

    Red Hat would like to thank Wjjzhang (Tencent.com Inc.) and Li Qiang (360.cn Inc.) for reporting CVE-2017-2615.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-2615
    CVE-2017-2620
    RHSA-2017:0454
    RHSA-2017:0454-00
    RHSA-2017:0454-01
    RHSA-2017:0454-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • kmod-kvm is earlier than 0:83-277.el5_11
  • AND kmod-kvm is signed with Red Hat redhatrelease2 key
  • kmod-kvm-debug is earlier than 0:83-277.el5_11
  • AND kmod-kvm-debug is signed with Red Hat redhatrelease2 key
  • kvm is earlier than 0:83-277.el5_11
  • AND kvm is signed with Red Hat redhatrelease2 key
  • kvm-qemu-img is earlier than 0:83-277.el5_11
  • AND kvm-qemu-img is signed with Red Hat redhatrelease2 key
  • kvm-tools is earlier than 0:83-277.el5_11
  • AND kvm-tools is signed with Red Hat redhatrelease2 key
  • BACK