Oval Definition:oval:org.mitre.oval:def:27175
Revision Date:2014-12-08Version:9
Title:RHSA-2013:1553 -- qemu-kvm security, bug fix, and enhancement update (Important)
Description:KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on AMD64 and Intel 64 systems that is built into the standard Red HatEnterprise Linux kernel. The qemu-kvm packages form the user-spacecomponent for running virtual machines using KVM.A buffer overflow flaw was found in the way QEMU processed the SCSI "REPORTLUNS" command when more than 256 LUNs were specified for a single SCSItarget. A privileged guest user could use this flaw to corrupt QEMU processmemory on the host, which could potentially result in arbitrary codeexecution on the host with the privileges of the QEMU process.(CVE-2013-4344)This issue was discovered by Asias He of Red Hat.These updated qemu-kvm packages include numerous bug fixes and variousenhancements. Space precludes documenting all of these changes in thisadvisory. Users are directed to the Red Hat Enterprise Linux 6.5 TechnicalNotes, linked to in the References, for information on the most significantof these changes.All qemu-kvm users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues and add theseenhancements. After installing this update, shut down all running virtualmachines. Once all virtual machines have shut down, start them again forthis update to take effect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:1553
CVE-2013-4344
RHSA-2013:1553
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):qemu-kvm
Definition Synopsis
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • qemu-guest-agent is earlier than 0:0.12.1.2-2.415.el6
  • OR qemu-img is earlier than 0:0.12.1.2-2.415.el6
  • OR qemu-kvm is earlier than 0:0.12.1.2-2.415.el6
  • OR qemu-kvm-tools is earlier than 0:0.12.1.2-2.415.el6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND qemu-kvm-debuginfo is earlier than 0:0.12.1.2-2.415.el6
  • BACK