RHSA-2010:0095: Important: rhev-hypervisor security and bug fix update
The rhev-hypervisor package provides a Red Hat Enterprise Virtualization(RHEV) Hypervisor ISO disk image. The RHEV Hypervisor is a dedicatedKernel-based Virtual Machine (KVM) hypervisor. It includes everythingnecessary to run and manage virtual machines: A subset of the Red HatEnterprise Linux operating environment and the Red Hat EnterpriseVirtualization Agent.Note: RHEV Hypervisor is only available for the Intel 64 and AMD64architectures with virtualization extensions.A flaw was found in the IPv6 Extension Header (EH) handlingimplementation in the Linux kernel. The skb->dst data structure was notproperly validated in the ipv6hopjumbo() function. This could possiblylead to a remote denial of service. (CVE-2007-4567)The Parallels Virtuozzo Containers team reported two flaws in the routingimplementation. If an attacker was able to cause a large enough number ofcollisions in the routing hash table (via specially-crafted packets) forthe emergency route flush to trigger, a deadlock could occur. Secondly, ifthe kernel routing cache was disabled, an uninitialized pointer would beleft behind after a route lookup, leading to a kernel panic.(CVE-2009-4272)A flaw was found in each of the following Intel PRO/1000 Linux drivers inthe Linux kernel: e1000 and e1000e. A remote attacker using packets largerthan the MTU could bypass the existing fragment check, resulting inpartial, invalid frames being passed to the network stack. These flawscould also possibly be used to trigger a remote denial of service.(CVE-2009-4536, CVE-2009-4538)A flaw was found in the Realtek r8169 Ethernet driver in the Linux kernel.Receiving overly-long frames with a certain revision of the network cardssupported by this driver could possibly result in a remote denial ofservice. (CVE-2009-4537)The x86 emulator implementation was missing a check for the CurrentPrivilege Level (CPL) and I/O Privilege Level (IOPL). A user in a guestcould leverage these flaws to cause a denial of service (guest crash) orpossibly escalate their privileges within that guest. (CVE-2010-0298,CVE-2010-0306)A flaw was found in the Programmable Interval Timer (PIT) emulation. Accessto the internal data structure pitstate, which represents the data stateof the emulated PIT, was not properly validated in the pitioportread()function. A privileged guest user could use this flaw to crash the host.(CVE-2010-0309)This updated package provides updated components that include fixes forsecurity issues; however, these issues have no security impact for RHEVHypervisor. These fixes are for kernel issues CVE-2006-6304, CVE-2009-2910,CVE-2009-3080, CVE-2009-3556, CVE-2009-3889, CVE-2009-3939, CVE-2009-4020,CVE-2009-4021, CVE-2009-4138, and CVE-2009-4141; ntp issue CVE-2009-3563;dbus issue CVE-2009-1189; dnsmasq issues CVE-2009-2957 and CVE-2009-2958;gnutls issue CVE-2009-2730; krb5 issue CVE-2009-4212; bind issue CVE-2010-0097; gzip issue CVE-2010-0001; openssl issues CVE-2009-2409 and CVE-2009-4355; and gcc issue CVE-2009-3736.This update also fixes the following bugs: on systems with a large number of disk devices, USB storage devices may get enumerated after "/dev/sdz", for example, "/dev/sdcd". This was nothandled by the udev rules, resulting in a missing "/dev/live" symboliclink, causing installations from USB media to fail. With this update, udevrules correctly handle USB storage devices on systems with a large numberof disk devices, which resolves this issue. (BZ#555083)As RHEV Hypervisor is based on KVM, the bug fixes from the KVM updateRHSA-2010:0088 have been included in this update:https://rhn.redhat.com/errata/RHSA-2010-0088.html Users of the Red Hat Enterprise Virtualization Hypervisor are advised toupgrade to this updated package, which corrects these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0095?
The severity of RHSA-2010:0095 is classified as important.
How do I fix RHSA-2010:0095?
To fix RHSA-2010:0095, you need to update the rhev-hypervisor package to the latest version provided by Red Hat.
What vulnerabilities does RHSA-2010:0095 address?
RHSA-2010:0095 addresses multiple vulnerabilities in the rhev-hypervisor package that could potentially allow for code execution.
Is RHSA-2010:0095 related to any specific software versions?
Yes, RHSA-2010:0095 specifically affects the versions of Red Hat Enterprise Virtualization Hypervisor prior to the fix.
When was RHSA-2010:0095 released?
RHSA-2010:0095 was released on March 29, 2010.