RHSA-2010:0271: Important: kvm security, bug fix and enhancement update
KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built forthe standard Red Hat Enterprise Linux kernel.A flaw was found in the way QEMU-KVM handled erroneous data provided bythe Linux virtio-net driver, used by guest operating systems. Due to adeficiency in the TSO (TCP segment offloading) implementation, a guest'svirtio-net driver would transmit improper data to a certain QEMU-KVMprocess on the host, causing the guest to crash. A remote attacker coulduse this flaw to send specially-crafted data to a target guest system,causing that guest to crash. (CVE-2010-0741)Additionally, these updated packages include numerous bug fixes andenhancements. Refer to the KVM chapter of the Red Hat Enterprise Linux 5.5Technical Notes for details:http://www.redhat.com/docs/en-US/RedHatEnterpriseLinux/5.5/html/TechnicalNotes/kvm.html All KVM users should upgrade to these updated packages, which resolve thisissue as well as fixing the bugs and adding the enhancements noted in theTechnical Notes. Note: The procedure in the Solution section must beperformed before this update will take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0271?
The severity of RHSA-2010:0271 is considered critical due to potential remote code execution vulnerabilities.
How do I fix RHSA-2010:0271?
To fix RHSA-2010:0271, update the affected KVM packages to version 83-164.el5 or later.
What software is affected by RHSA-2010:0271?
RHSA-2010:0271 affects KVM, kmod-kvm, kvm-qemu-img, and kvm-tools packages on Red Hat Enterprise Linux.
When was RHSA-2010:0271 released?
RHSA-2010:0271 was released to address vulnerabilities on March 31, 2010.
What impact does RHSA-2010:0271 have on my system?
RHSA-2010:0271 can potentially allow an attacker to execute arbitrary code on the host system through KVM.