RHSA-2017:1209: Important: rhev-hypervisor bug fix and enhancement update for RHEV 3.6.11
The rhev-hypervisor package provides a Red Hat Enterprise VirtualizationHypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisoris a dedicated Kernel-based Virtual Machine (KVM) hypervisor. It includeseverything necessary to run and manage virtual machines: A subset of theRed Hat Enterprise Linux operating environment and the Red Hat EnterpriseVirtualization Agent.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074) Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.Note: Red Hat Enterprise Virtualization Hypervisor is only available forthe Intel 64 and AMD64 architectures with virtualization extensions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:1209?
The severity of RHSA-2017:1209 is classified as important.
How do I fix RHSA-2017:1209?
To fix RHSA-2017:1209, update the rhev-hypervisor package to the latest version available for your system.
Which versions of rhev-hypervisor are affected by RHSA-2017:1209?
RHSA-2017:1209 affects rhev-hypervisor versions up to 7.3-20170425.0.el7e and 7.3-20170425.0.el6e.
What is the main impact of RHSA-2017:1209?
The main impact of RHSA-2017:1209 involves security vulnerabilities that could affect the stability and security of the hypervisor environment.
Is there a workaround for RHSA-2017:1209?
There are no specific workarounds for RHSA-2017:1209; updating the package is recommended to address the vulnerabilities.