First published: Tue Oct 22 2019(Updated: )
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.<br>Security Fix(es):<br><li> QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)</li> <li> QEMU: qxl: null pointer dereference while releasing spice resources (CVE-2019-12155)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> ccid: Fix incorrect dwProtocol advertisement of T=0 (BZ#1729880)</li> <li> QEMU gets stuck on resume/cont call from libvirt (BZ#1741937)</li> <li> [v2v] Migration performance regression (BZ#1743322)</li> <li> qemu, qemu-img fail to detect alignment with XFS and Gluster/XFS on 4k block device (BZ#1745443)</li> <li> qemu-kvm: backport cpuidle-haltpoll support (BZ#1746282)</li> <li> qemu aborts in blockCommit: qemu-kvm: block.c:3486 (BZ#1750322)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qemu-kvm-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-img-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-common-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-rhev-debuginfo | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-tools-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-img-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-common-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-rhev-debuginfo | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
redhat/qemu-kvm-tools-rhev | <2.12.0-33.el7_7.4 | 2.12.0-33.el7_7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:3179 is classified as important.
To fix RHSA-2019:3179, you should update the affected packages to version 2.12.0-33.el7_7.4 or later.
The affected packages for RHSA-2019:3179 include qemu-kvm-rhev, qemu-img-rhev, qemu-kvm-common-rhev, and various others related to KVM in Red Hat.
RHSA-2019:3179 is primarily relevant for users running KVM on Red Hat Enterprise Linux environments.
RHSA-2019:3179 addresses a security vulnerability in the KVM virtualization component of Linux.