First published: Wed Jun 03 2015(Updated: )
The virtio-win package provides paravirtualized network drivers for most<br>Microsoft Windows operating systems. Paravirtualized drivers are<br>virtualization-aware drivers used by fully virtualized guests running on<br>Red Hat Enterprise Linux. Fully virtualized guests using the<br>paravirtualized drivers gain significantly better I/O performance than<br>fully virtualized guests running without the drivers.<br>It was found that the Windows Virtio NIC driver did not sufficiently<br>sanitize the length of the incoming IP packets, as demonstrated by a packet<br>with IP options present but the overall packet length not being adjusted to<br>reflect the length of those options. A remote attacker able to send a<br>specially crafted IP packet to the guest could use this flaw to crash that<br>guest. (CVE-2015-3215)<br>Red Hat would like to thank Google Project Zero for reporting this issue.<br>This update also fixes the following bugs:<br><li> When creating a Windows guest using virtio drivers and direct Logical</li> Unit Number (LUN) access with more than 4 SCSI disks under one<br>virtio-scsi-pci controller, the guest terminated unexpectedly with a stop<br>error, also known as the blue screen of death. This update increases the<br>maximum amount of LUNs per a single virtio-scsi-pci controller has been<br>increased to 254, which prevents the described crash from occurring.<br>(BZ#1210196)<br><li> The license.txt file in the virtio-win build has been updated to include</li> the correct year number in the copyright information section. (BZ#1210195)<br>All virtio-win users are advised to upgrade to this updated package, which<br>contains backported patches to correct these issues.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/virtio-win | <1.7.4-1.el6_6 | 1.7.4-1.el6_6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2015:1043 is classified as important.
To fix RHSA-2015:1043, update the virtio-win package to version 1.7.4-1.el6_6 or later.
RHSA-2015:1043 affects fully virtualized guests running on Red Hat Enterprise Linux using the virtio-win package.
The virtio-win package provides paravirtualized network drivers for most Microsoft Windows operating systems.
There is no specified workaround for RHSA-2015:1043; updating the package is recommended.