RHSA-2020:4055: Important: qemu-kvm security update
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.Security Fix(es): QEMU: usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qemu-kvmto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.448.el6_6.9 - Upgrade
Upgrade
redhat/qemu-guest-agentto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.448.el6_6.9 - Upgrade
Upgrade
redhat/qemu-imgto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.448.el6_6.9 - Upgrade
Upgrade
redhat/qemu-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.448.el6_6.9 - Upgrade
Upgrade
redhat/qemu-kvm-toolsto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.448.el6_6.9
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4055?
The severity of RHSA-2020:4055 is classified as important.
How do I fix RHSA-2020:4055?
To fix RHSA-2020:4055, upgrade your qemu-kvm, qemu-guest-agent, qemu-img, and related packages to version 0.12.1.2-2.448.el6_6.9 or later.
Which packages are affected by RHSA-2020:4055?
The affected packages under RHSA-2020:4055 include qemu-kvm, qemu-guest-agent, qemu-img, qemu-kvm-debuginfo, and qemu-kvm-tools.
What type of vulnerability is addressed in RHSA-2020:4055?
RHSA-2020:4055 addresses an out-of-bounds read/write access issue in QEMU.
Where can I find more information about RHSA-2020:4055?
More information about RHSA-2020:4055 can be found in the Red Hat advisory and associated resources.