RHSA-2010:0271: Important: kvm security, bug fix and enhancement update

Published Mar 30, 2010
·
Updated

KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built forthe standard Red Hat Enterprise Linux kernel.A flaw was found in the way QEMU-KVM handled erroneous data provided bythe Linux virtio-net driver, used by guest operating systems. Due to adeficiency in the TSO (TCP segment offloading) implementation, a guest'svirtio-net driver would transmit improper data to a certain QEMU-KVMprocess on the host, causing the guest to crash. A remote attacker coulduse this flaw to send specially-crafted data to a target guest system,causing that guest to crash. (CVE-2010-0741)Additionally, these updated packages include numerous bug fixes andenhancements. Refer to the KVM chapter of the Red Hat Enterprise Linux 5.5Technical Notes for details:http://www.redhat.com/docs/en-US/RedHatEnterpriseLinux/5.5/html/TechnicalNotes/kvm.html All KVM users should upgrade to these updated packages, which resolve thisissue as well as fixing the bugs and adding the enhancements noted in theTechnical Notes. Note: The procedure in the Solution section must beperformed before this update will take effect.

Affected Software

5 affected componentsFixes available
redhat/kvm<83-164.el5
83-164.el5
redhat/kmod-kvm<83-164.el5
83-164.el5
redhat/kvm<83-164.el5
83-164.el5
redhat/kvm-qemu-img<83-164.el5
83-164.el5
redhat/kvm-tools<83-164.el5
83-164.el5

Remediation

Event History

Mar 30, 2010
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2010:0271?

The severity of RHSA-2010:0271 is considered critical due to potential remote code execution vulnerabilities.

2

How do I fix RHSA-2010:0271?

To fix RHSA-2010:0271, update the affected KVM packages to version 83-164.el5 or later.

3

What software is affected by RHSA-2010:0271?

RHSA-2010:0271 affects KVM, kmod-kvm, kvm-qemu-img, and kvm-tools packages on Red Hat Enterprise Linux.

4

When was RHSA-2010:0271 released?

RHSA-2010:0271 was released to address vulnerabilities on March 31, 2010.

5

What impact does RHSA-2010:0271 have on my system?

RHSA-2010:0271 can potentially allow an attacker to execute arbitrary code on the host system through KVM.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203