RHSA-2021:0934: Moderate: qemu-kvm-rhev security update
KVM (Kernel-based Virtual Machine) is a full virtualization solution for<br>Linux on a variety of architectures. The qemu-kvm-rhev packages provide the<br>user-space component for running virtual machines that use KVM in<br>environments managed by Red Hat products.<br>Security Fix(es):<br><li> slirp: use-after-free in ipreass() function in ipinput.c</li> (CVE-2020-1983)<br><li> reachable assertion failure in nettxpktaddrawfragment() in</li> hw/net/nettxpkt.c (CVE-2020-16092)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0934?
The severity of RHSA-2021:0934 is categorized as critical due to its potential impact on system security.
How do I fix RHSA-2021:0934?
To fix RHSA-2021:0934, update the affected qemu-kvm-rhev packages to version 2.12.0-48.el7_9.2 or later.
Which packages are affected by RHSA-2021:0934?
Affected packages include qemu-kvm-rhev, qemu-img-rhev, and qemu-kvm-common-rhev versions prior to 2.12.0-48.el7_9.2.
What systems are impacted by RHSA-2021:0934?
RHSA-2021:0934 impacts systems running Red Hat Enterprise Linux with KVM virtualization.
Is a reboot required after applying the fix for RHSA-2021:0934?
Yes, a reboot may be required after updating the packages to ensure all changes take effect properly.