SCIENTIFIC-LINUX-ERRATA Archives

August 2010

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Fri, 20 Aug 2010 14:17:50 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (100 lines)
Synopsis:	Important: kvm security and bug fix update
Issue date:	2010-08-19
CVE Names:	CVE-2010-0431 CVE-2010-0435 CVE-2010-2784

It was found that QEMU-KVM on the host did not validate all pointers
provided from a guest system's QXL graphics card driver. A privileged 
guest user could use this flaw to cause the host to dereference an 
invalid pointer, causing the guest to crash (denial of service) or, 
possibly, resulting in the privileged guest user escalating their 
privileges on the host. (CVE-2010-0431)

A flaw was found in QEMU-KVM, allowing the guest some control over the
index used to access the callback array during sub-page MMIO
initialization. A privileged guest user could use this flaw to crash the
guest (denial of service) or, possibly, escalate their privileges on the
host. (CVE-2010-2784)

A NULL pointer dereference flaw was found when the host system had a
processor with the Intel VT-x extension enabled. A privileged guest user
could use this flaw to trick the host into emulating a certain 
instruction, which could crash the host (denial of service). (CVE-2010-0435)

This update also fixes the following bugs:

* running a "qemu-img" check on a faulty virtual machine image ended 
with a segmentation fault. With this update, the segmentation fault no 
longer occurs when running the "qemu-img" check. (BZ#610342)

* when attempting to transfer a file between two guests that were joined 
in the same virtual LAN (VLAN), the receiving guest unexpectedly quit. 
With this update, the transfer completes successfully. (BZ#610343)

* installation of a system was occasionally failing in KVM. This was 
caused by KVM using wrong permissions for large guest pages. With this 
update, the installation completes successfully. (BZ#616796)

* previously, the migration process would fail for a virtual machine
because the virtual machine could not map all the memory. This was 
caused by a conflict that was initiated when a virtual machine was 
initially run and then migrated right away. With this update, the 
conflict no longer occurs and the migration process no longer fails. 
(BZ#618205)

* using a thinly provisioned VirtIO disk on iSCSI storage and performing 
a "qemu-img" check during an "e_no_space" event returned cluster errors. 
With this update, the errors no longer appear. (BZ#618206)


NOTE: The following procedure must be performed before this update will 
take effect:

1) Stop all KVM guest virtual machines.

2) Either reboot the hypervisor machine or, as the root user, remove 
(using "modprobe -r [module]") and reload (using "modprobe [module]") 
all of the following modules which are currently running (determined 
using "lsmod"): kvm, ksm, kvm-intel or kvm-amd.

3) Restart the KVM guest virtual machines.

SL 5.x

     SRPMS:
kvm-83-164.el5_5.21.src.rpm
     x86_64:
kmod-kvm-83-164.el5_5.21.x86_64.rpm
kvm-83-164.el5_5.21.x86_64.rpm
kvm-qemu-img-83-164.el5_5.21.x86_64.rpm
kvm-tools-83-164.el5_5.21.x86_64.rpm
   Dependancies for SL 50-53:
celt051-0.5.1.3-0.el5.i386.rpm
celt051-0.5.1.3-0.el5.x86_64.rpm
celt051-devel-0.5.1.3-0.el5.i386.rpm
celt051-devel-0.5.1.3-0.el5.x86_64.rpm
etherboot-pxes-5.4.4-13.el5.x86_64.rpm
etherboot-roms-5.4.4-13.el5.x86_64.rpm
etherboot-roms-kvm-5.4.4-13.el5.x86_64.rpm
etherboot-zroms-5.4.4-13.el5.x86_64.rpm
etherboot-zroms-kvm-5.4.4-13.el5.x86_64.rpm
log4cpp-1.0-9.el5.i386.rpm
log4cpp-1.0-9.el5.x86_64.rpm
log4cpp-devel-1.0-9.el5.i386.rpm
log4cpp-devel-1.0-9.el5.x86_64.rpm
log4cpp-docs-1.0-9.el5.x86_64.rpm
qcairo-1.8.7.1-3.el5.i386.rpm
qcairo-1.8.7.1-3.el5.x86_64.rpm
qcairo-devel-1.8.7.1-3.el5.i386.rpm
qcairo-devel-1.8.7.1-3.el5.x86_64.rpm
qffmpeg-devel-0.4.9-0.15.20080908.el5.i386.rpm
qffmpeg-devel-0.4.9-0.15.20080908.el5.x86_64.rpm
qffmpeg-libs-0.4.9-0.15.20080908.el5.i386.rpm
qffmpeg-libs-0.4.9-0.15.20080908.el5.x86_64.rpm
qpixman-0.13.3-4.el5.i386.rpm
qpixman-0.13.3-4.el5.x86_64.rpm
qpixman-devel-0.13.3-4.el5.i386.rpm
qpixman-devel-0.13.3-4.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2