First published: Wed Jul 25 2018(Updated: )
KVM (Kernel-based Virtual Machine) is a full virtualization solution for<br>Linux on a variety of architectures. The qemu-kvm-rhev packages provide the<br>user-space component for running virtual machines that use KVM in<br>environments managed by Red Hat products.<br>Security fix(es):<br><li> An industry-wide issue was found in the way many modern microprocessor</li> designs have implemented speculative execution of Load & Store instructions<br>(a commonly used performance optimization). It relies on the presence of a<br>precisely-defined instruction sequence in the privileged code as well as<br>the fact that memory read from address to which a recent memory write has<br>occurred may see an older value and subsequently cause an update into the<br>microprocessor's data cache even for speculatively executed instructions<br>that never actually commit (retire). As a result, an unprivileged attacker<br>could use this flaw to read privileged memory by conducting targeted cache<br>side-channel attacks. (CVE-2018-3639)<br>Acknowledgements:<br>Red Hat would like to thank Ken Johnson (Microsoft Security Response Center)<br>and Jann Horn (Google Project Zero) for reporting this issue.<br>Note: This is the qemu-kvm-rhev side of the CVE-2018-3639 mitigation that<br>includes support for guests running on hosts with AMD processors.<br>For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, refer to the CVE page(s) listed in<br>the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qemu-img-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-common-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-rhev-debuginfo | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-tools-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-img-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-common-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-rhev-debuginfo | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
redhat/qemu-kvm-tools-rhev | <2.10.0-21.el7_5.4 | 2.10.0-21.el7_5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.