RHSA-2020:1116: Important: qemu-kvm security, bug fix, and enhancement update
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.Security Fix(es): QEMU: slirp: OOB buffer access while emulating tcp protocols in tcpemu() (CVE-2020-7039) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qemu-kvmto a version that resolves this vulnerability.Fixed in 1.5.3-173.el7 - Upgrade
Upgrade
redhat/qemu-imgto a version that resolves this vulnerability.Fixed in 1.5.3-173.el7 - Upgrade
Upgrade
redhat/qemu-kvm-commonto a version that resolves this vulnerability.Fixed in 1.5.3-173.el7 - Upgrade
Upgrade
redhat/qemu-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.3-173.el7 - Upgrade
Upgrade
redhat/qemu-kvm-toolsto a version that resolves this vulnerability.Fixed in 1.5.3-173.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1116?
The severity of RHSA-2020:1116 is classified as important.
How do I fix RHSA-2020:1116?
To fix RHSA-2020:1116, you need to update the qemu-kvm, qemu-img, and other affected packages to version 1.5.3-173.el7 or later.
Which packages are affected by RHSA-2020:1116?
The affected packages include qemu-kvm, qemu-img, qemu-kvm-common, qemu-kvm-debuginfo, and qemu-kvm-tools in versions prior to 1.5.3-173.el7.
What type of vulnerability is addressed in RHSA-2020:1116?
RHSA-2020:1116 addresses an out-of-bounds buffer access vulnerability in QEMU.
Where can I find more information about RHSA-2020:1116?
More information about RHSA-2020:1116 is available in the official Red Hat advisory and security notices.