RHSA-2019:2425: Important: qemu-kvm-rhev security and bug fix update
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.<br>Security Fix(es):<br><li> QEMU: slirp: heap buffer overflow in tcpemu() (CVE-2019-6778)</li> <li> QEMU: rtl8139: integer overflow leads to buffer overflow (CVE-2018-17958)</li> <li> QEMU: net: ignore packets with large size (CVE-2018-17963)</li> <li> QEMU: seccomp: blacklist is not applied to all threads (CVE-2018-15746)</li> <li> QEMU: scsi-generic: possible OOB access while handling inquiry request (CVE-2019-6501)</li> <li> QEMU: slirp: information leakage in tcpemu() due to uninitialized stack variables (CVE-2019-9824)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Update qemu-kvm-rhev for RHEL 7.7 compatibility [OSP-14] (BZ#1728358)</li> <li> Update qemu-kvm-rhev for RHEL 7.7 compatibility [OSP-13] (BZ#1728359)</li> <li> Update qemu-kvm-rhev for RHEL 7.7 compatibility [OSP-10] (BZ#1728360)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2425?
The severity of RHSA-2019:2425 is considered critical due to the potential for an attacker to execute arbitrary code.
How do I fix RHSA-2019:2425?
To fix RHSA-2019:2425, you should update the qemu-kvm-rhev and related packages to version 2.12.0-33.el7 or later.
Which packages are affected by RHSA-2019:2425?
The affected packages include qemu-kvm-rhev, qemu-img-rhev, and qemu-kvm-common-rhev, among others, all prior to version 2.12.0-33.el7.
Is RHSA-2019:2425 relevant for my system?
RHSA-2019:2425 is relevant for any system using KVM virtualization and running vulnerable versions of the specified packages.
What vulnerabilities does RHSA-2019:2425 address?
RHSA-2019:2425 addresses critical vulnerabilities that could allow an attacker to gain control of the host system via crafted virtual machine images.