RHSA-2020:3267: Low: qemu-kvm-rhev security, bug fix, and enhancement update
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.Security Fix(es): CVE-2019-20382 QEMU: vnc: memory leakage upon disconnect For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Add support for newer glusterfs (BZ#1802216) Backport: Passthrough host CPU microcode version to KVM guest if using CPU passthrough to RHEL 7.7/7.8 (BZ#1791653) After hot unplug virtio-net and vfio nic, hot plug vfio-pci device fails in Win2019 guest (BZ#1721403) qemu-kvm-rhev: Qemu: seccomp: blacklist is not applied to all threads (BZ#1618504) Fix overzealous I/O request splitting performance regression (BZ#1819253)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3267?
The severity of RHSA-2020:3267 is classified as important.
What products are affected by RHSA-2020:3267?
RHSA-2020:3267 affects various versions of qemu-kvm-rhev, qemu-img-rhev, and qemu-kvm-common-rhev packages.
How do I fix RHSA-2020:3267?
To fix RHSA-2020:3267, update the affected packages to version 2.12.0-48.el7 or later.
Is there a workaround for RHSA-2020:3267?
There are no specific workarounds recommended for RHSA-2020:3267, and patching is the suggested resolution.
What vulnerabilities are addressed in RHSA-2020:3267?
RHSA-2020:3267 addresses multiple security vulnerabilities in the KVM packages, enhancing overall security.