Subject: | |
From: | |
Reply To: | |
Date: | Wed, 6 Jul 2011 14:11:55 -0500 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Synopsis: Important: qemu-kvm security, bug fix, and enhancement update
Issue date: 2011-05-19
CVE Names: CVE-2011-1750 CVE-2011-1751
KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space
component for running virtual machines using KVM.
It was found that the virtio-blk driver in qemu-kvm did not properly
validate read and write requests from guests. A privileged guest user
could use this flaw to crash the guest or, possibly, execute arbitrary
code on the host. (CVE-2011-1750)
It was found that the PIIX4 Power Management emulation layer in qemu-kvm
did not properly check for hot plug eligibility during device removals.
A privileged guest user could use this flaw to crash the guest or,
possibly, execute arbitrary code on the host. (CVE-2011-1751)
This update also fixes several bugs and adds various enhancements.
All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues, and fix the bugs and
add the enhancements.
After installing this update, shut down all running virtual machines.
Once all virtual machines have shut down, start them again for this
update to take effect.
SL 6.x
SRPMS:
qemu-kvm-0.12.1.2-2.160.el6.src.rpm
x86_64:
qemu-img-0.12.1.2-2.160.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.160.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.160.el6.x86_64.rpm
Dependancies:
spice-protocol-0.8.0-1.el6.noarch.rpm
spice-server-0.8.0-1.el6.x86_64.rpm
spice-server-devel-0.8.0-1.el6.x86_64.rpm
vgabios-0.6b-3.6.el6.noarch.rpm
- Scientific Linux Development Team
|
|
|