RHSA-2020:4167: Important: qemu-kvm-rhev security update
KVM (Kernel-based Virtual Machine) is a full virtualization solution forLinux on a variety of architectures. The qemu-kvm-rhev packages provide theuser-space component for running virtual machines that use KVM inenvironments managed by Red Hat products.Security Fix(es): usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) vnc: memory leakage upon disconnect (CVE-2019-20382) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4167?
The severity of RHSA-2020:4167 is classified as important.
How do I fix RHSA-2020:4167?
To fix RHSA-2020:4167, you should update the affected packages to version 2.12.0-48.el7_9.1 or later.
Which packages are affected by RHSA-2020:4167?
RHSA-2020:4167 affects packages such as qemu-kvm-rhev, qemu-img-rhev, and qemu-kvm-common-rhev.
Is RHSA-2020:4167 applicable to all architectures?
RHSA-2020:4167 is applicable to x86_64 and ppc64le architectures.
What vulnerabilities does RHSA-2020:4167 address?
RHSA-2020:4167 addresses multiple vulnerabilities in the KVM implementation used in Red Hat products.