RHSA-2020:2730: Important: qemu-kvm-rhev security update
KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on a variety of architectures. The qemu-kvm-rhev packages provide theuser-space component for running virtual machines that use KVM inenvironments managed by Red Hat products.Security Fix(es): Slirp: OOB buffer access while emulating tcp protocols in tcpemu() (CVE-2020-7039) Slirp: potential OOB access due to unsafe snprintf() usages (CVE-2020-8608)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2730?
The severity of RHSA-2020:2730 is classified as important.
How do I fix RHSA-2020:2730?
To fix RHSA-2020:2730, update the affected packages to version 2.12.0-44.el7_8.1 or later.
What products are affected by RHSA-2020:2730?
The affected products include qemu-kvm-rhev, qemu-img-rhev, and qemu-kvm-common-rhev versions prior to 2.12.0-44.el7_8.1.
Is there a security risk associated with RHSA-2020:2730?
Yes, RHSA-2020:2730 addresses vulnerabilities in KVM that could potentially allow unauthorized access or elevation of privileges.
When was RHSA-2020:2730 released?
RHSA-2020:2730 was released on September 17, 2020.