Lucene search

K
osvGoogleOSV:ALSA-2021:5238
HistoryDec 21, 2021 - 9:11 a.m.

Low: virt:rhel and virt-devel:rhel security update

2021-12-2109:11:21
Google
osv.dev
2

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.4%

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c (CVE-2021-3930)

  • QEMU: net: e1000: infinite loop while processing transmit descriptors (CVE-2021-20257)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.