SCIENTIFIC-LINUX-ERRATA Archives

April 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 21 Apr 2015 19:24:13 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (37 lines)
Synopsis:          Important: qemu-kvm security and bug fix update
Advisory ID:       SLSA-2015:0867-1
Issue Date:        2015-04-21
CVE Numbers:       CVE-2014-8106
--

It was found that the Cirrus blit region checks were insufficient. A
privileged guest user could use this flaw to write outside of VRAM-
allocated buffer boundaries in the host's QEMU process address space with
attacker-provided data. (CVE-2014-8106)

This update also fixes the following bug:

* Previously, the effective downtime during the last phase of a live
migration would sometimes be much higher than the maximum downtime
specified by 'migration_downtime' in vdsm.conf. This problem has been
corrected. The value of 'migration_downtime' is now honored and the
migration is aborted if the downtime cannot be achieved.

After installing this update, shut down all running virtual machines. Once
all virtual machines have shut down, start them again for this update to
take effect.
--

SL6
  x86_64
    qemu-guest-agent-0.12.1.2-2.448.el6_6.2.x86_64.rpm
    qemu-img-0.12.1.2-2.448.el6_6.2.x86_64.rpm
    qemu-kvm-0.12.1.2-2.448.el6_6.2.x86_64.rpm
    qemu-kvm-debuginfo-0.12.1.2-2.448.el6_6.2.x86_64.rpm
    qemu-kvm-tools-0.12.1.2-2.448.el6_6.2.x86_64.rpm
  i386
    qemu-guest-agent-0.12.1.2-2.448.el6_6.2.i686.rpm
    qemu-kvm-debuginfo-0.12.1.2-2.448.el6_6.2.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2