RHSA-2020:4079: Important: qemu-kvm security update
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.Security Fix(es): QEMU: usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) QEMU: slirp: use-after-free in ipreass() function in ipinput.c (CVE-2020-1983) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4079?
The severity of RHSA-2020:4079 is classified as important.
How do I fix RHSA-2020:4079?
To fix RHSA-2020:4079, update the qemu-kvm, qemu-img, and related packages to version 1.5.3-175.el7_9.1.
Which software packages are affected by RHSA-2020:4079?
The affected software packages in RHSA-2020:4079 include qemu-kvm, qemu-img, qemu-kvm-common, and others.
What issues does RHSA-2020:4079 address?
RHSA-2020:4079 addresses an out-of-bounds read/write access vulnerability in QEMU.
What platforms are impacted by RHSA-2020:4079?
RHSA-2020:4079 affects KVM on various architectures, specifically those utilizing the mentioned packages.