SCIENTIFIC-LINUX-ERRATA Archives

July 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 28 Jul 2015 14:27:45 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (50 lines)
Synopsis:          Important: qemu-kvm security and bug fix update
Advisory ID:       SLSA-2015:1507-1
Issue Date:        2015-07-27
CVE Numbers:       CVE-2015-3214
                   CVE-2015-5154
--

A heap buffer overflow flaw was found in the way QEMU's IDE subsystem
handled I/O buffer access while processing certain ATAPI commands. A
privileged guest user in a guest with the CDROM drive enabled could
potentially use this flaw to execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.
(CVE-2015-5154)

An out-of-bounds memory access flaw, leading to memory corruption or
possibly an information leak, was found in QEMU's pit_ioport_read()
function. A privileged guest user in a QEMU guest, which had QEMU PIT
emulation enabled, could potentially, in rare cases, use this flaw to
execute arbitrary code on the host with the privileges of the hosting QEMU
process. (CVE-2015-3214)

This update also fixes the following bug:

* Due to an incorrect implementation of portable memory barriers, the QEMU
emulator in some cases terminated unexpectedly when a virtual disk was
under heavy I/O load. This update fixes the implementation in order to
achieve correct synchronization between QEMU's threads. As a result, the
described crash no longer occurs.

After installing this update, shut down all running virtual machines. Once
all virtual machines have shut down, start them again for this update to
take effect.
--

SL7
  x86_64
    libcacard-1.5.3-86.el7_1.5.i686.rpm
    libcacard-1.5.3-86.el7_1.5.x86_64.rpm
    qemu-img-1.5.3-86.el7_1.5.x86_64.rpm
    qemu-kvm-1.5.3-86.el7_1.5.x86_64.rpm
    qemu-kvm-common-1.5.3-86.el7_1.5.x86_64.rpm
    qemu-kvm-debuginfo-1.5.3-86.el7_1.5.i686.rpm
    qemu-kvm-debuginfo-1.5.3-86.el7_1.5.x86_64.rpm
    qemu-kvm-tools-1.5.3-86.el7_1.5.x86_64.rpm
    libcacard-devel-1.5.3-86.el7_1.5.i686.rpm
    libcacard-devel-1.5.3-86.el7_1.5.x86_64.rpm
    libcacard-tools-1.5.3-86.el7_1.5.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2