Synopsis:          Moderate: qemu-kvm security update
Advisory ID:       SLSA-2016:1585-1
Issue Date:        2016-08-09
CVE Numbers:       CVE-2016-5403
--

Security Fix(es):

* Quick emulator(Qemu) built with the virtio framework is vulnerable to an
unbounded memory allocation issue. It was found that a malicious guest
user could submit more requests than the virtqueue size permits.
Processing a request allocates a VirtQueueElement and therefore causes
unbounded memory allocation on the host controlled by the guest.
(CVE-2016-5403)
--

SL6
  x86_64
    qemu-guest-agent-0.12.1.2-2.491.el6_8.3.x86_64.rpm
    qemu-img-0.12.1.2-2.491.el6_8.3.x86_64.rpm
    qemu-kvm-0.12.1.2-2.491.el6_8.3.x86_64.rpm
    qemu-kvm-debuginfo-0.12.1.2-2.491.el6_8.3.x86_64.rpm
    qemu-kvm-tools-0.12.1.2-2.491.el6_8.3.x86_64.rpm
  i386
    qemu-guest-agent-0.12.1.2-2.491.el6_8.3.i686.rpm
    qemu-kvm-debuginfo-0.12.1.2-2.491.el6_8.3.i686.rpm

Additionally, releases 6.0 - 6.7 required the following packages
already available in SL6.8 for dependencies:
  x86_64
    glusterfs-3.7.5-19.el6.x86_64.rpm
    glusterfs-api-3.7.5-19.el6.x86_64.rpm
    glusterfs-api-devel-3.7.5-19.el6.x86_64.rpm
    glusterfs-cli-3.7.5-19.el6.x86_64.rpm
    glusterfs-client-xlators-3.7.5-19.el6.x86_64.rpm
    glusterfs-devel-3.7.5-19.el6.x86_64.rpm
    glusterfs-fuse-3.7.5-19.el6.x86_64.rpm
    glusterfs-ganesha-3.7.5-19.el6.x86_64.rpm
    glusterfs-libs-3.7.5-19.el6.x86_64.rpm
    glusterfs-rdma-3.7.5-19.el6.x86_64.rpm
    glusterfs-resource-agents-3.7.5-19.el6.noarch.rpm
    glusterfs-server-3.7.5-19.el6.x86_64.rpm
    nfs-ganesha-2.2.0-12.el6.x86_64.rpm
    nfs-ganesha-gluster-2.2.0-12.el6.x86_64.rpm
    python-argparse-1.2.1-2.1.el6.noarch.rpm
    pyxattr-0.5.0-1.el6.x86_64.rpm
    userspace-rcu-0.7.9-2.el6rhs.x86_64.rpm
    userspace-rcu-devel-0.7.9-2.el6rhs.x86_64.rpm

- Scientific Linux Development Team