Oval Definition:oval:org.mitre.oval:def:25091
Revision Date:2015-04-13Version:12
Title:RHSA-2014:0927: qemu-kvm security and bug fix update (Moderate)
Description:KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on AMD64 and Intel 64 systems. The qemu-kvm package provides theuser-space component for running virtual machines using KVM.Two integer overflow flaws were found in the QEMU block driver for QCOWversion 1 disk images. A user able to alter the QEMU disk image filesloaded by a guest could use either of these flaws to corrupt QEMU processmemory on the host, which could potentially result in arbitrary codeexecution on the host with the privileges of the QEMU process.(CVE-2014-0222, CVE-2014-0223)Multiple buffer overflow, input validation, and out-of-bounds write flawswere found in the way virtio, virtio-net, virtio-scsi, usb, and hpetdrivers of QEMU handled state loading after migration. A user able to alterthe savevm data (either on the disk or over the wire during migration)could use either of these flaws to corrupt QEMU process memory on the(destination) host, which could potentially result in arbitrary codeexecution on the host with the privileges of the QEMU process.(CVE-2013-4148, CVE-2013-4149, CVE-2013-4150, CVE-2013-4151, CVE-2013-4527,CVE-2013-4529, CVE-2013-4535, CVE-2013-4536, CVE-2013-4541, CVE-2013-4542,CVE-2013-6399, CVE-2014-0182, CVE-2014-3461)These issues were discovered by Michael S. Tsirkin, Anthony Liguori andMichael Roth of Red Hat: CVE-2013-4148, CVE-2013-4149, CVE-2013-4150,CVE-2013-4151, CVE-2013-4527, CVE-2013-4529, CVE-2013-4535, CVE-2013-4536,CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, andCVE-2014-3461.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:0927
CVE-2013-4148
CVE-2013-4149
CVE-2013-4150
CVE-2013-4151
CVE-2013-4527
CVE-2013-4529
CVE-2013-4535
CVE-2013-4536
CVE-2013-4541
CVE-2013-4542
CVE-2013-6399
CVE-2014-0182
CVE-2014-0222
CVE-2014-0223
CVE-2014-3461
RHSA-2014:0927-01
Platform(s):CentOS Linux 7
Red Hat Enterprise Linux 7
Product(s):qemu-kvm
Definition Synopsis
  • Red Hat Enterprise Linux 7 and CentOS Linux 7 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages match section
  • libcacard is earlier than 10:1.5.3-60.el7_0.5
  • OR libcacard-devel is earlier than 10:1.5.3-60.el7_0.5
  • OR libcacard-tools is earlier than 10:1.5.3-60.el7_0.5
  • OR qemu-guest-agent is earlier than 10:1.5.3-60.el7_0.5
  • OR qemu-img is earlier than 10:1.5.3-60.el7_0.5
  • OR qemu-kvm is earlier than 10:1.5.3-60.el7_0.5
  • OR qemu-kvm-common is earlier than 10:1.5.3-60.el7_0.5
  • OR qemu-kvm-tools is earlier than 10:1.5.3-60.el7_0.5
  • Red Hat Enterprise Linux 7 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • AND qemu-kvm-debuginfo is earlier than 10:1.5.3-60.el7_0.5
  • BACK