RHSA-2019:3179: Important: qemu-kvm-rhev security and bug fix update
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.Security Fix(es): QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) QEMU: qxl: null pointer dereference while releasing spice resources (CVE-2019-12155) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): ccid: Fix incorrect dwProtocol advertisement of T=0 (BZ#1729880) QEMU gets stuck on resume/cont call from libvirt (BZ#1741937) [v2v] Migration performance regression (BZ#1743322) qemu, qemu-img fail to detect alignment with XFS and Gluster/XFS on 4k block device (BZ#1745443) qemu-kvm: backport cpuidle-haltpoll support (BZ#1746282) qemu aborts in blockCommit: qemu-kvm: block.c:3486 (BZ#1750322)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3179?
The severity of RHSA-2019:3179 is classified as important.
How do I fix RHSA-2019:3179?
To fix RHSA-2019:3179, you should update the affected packages to version 2.12.0-33.el7_7.4 or later.
Which packages are affected by RHSA-2019:3179?
The affected packages for RHSA-2019:3179 include qemu-kvm-rhev, qemu-img-rhev, qemu-kvm-common-rhev, and various others related to KVM in Red Hat.
Is RHSA-2019:3179 relevant for all Red Hat users?
RHSA-2019:3179 is primarily relevant for users running KVM on Red Hat Enterprise Linux environments.
What type of vulnerability is addressed by RHSA-2019:3179?
RHSA-2019:3179 addresses a security vulnerability in the KVM virtualization component of Linux.