Lucene search

K
osvGoogleOSV:RLSA-2024:4351
HistoryJul 15, 2024 - 12:17 p.m.

Low: virt:rhel and virt-devel:rhel security and bug fix update

2024-07-1512:17:49
Google
osv.dev
7
kvm
linux
security fix
bug fix
virnetclientioeventloop
user-space components
apis
stack use-after-free
sigstop
jira:rocky linux-36064

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

Low

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix:

  • virt:libvirt: stack use-after-free in virNetClientIOEventLoop (CVE-2024-4418)

Bug fix:

  • virsh destroy with --graceful destroyed a paused guest (qemu process paused by SIGSTOP) (JIRA:Rocky Linux-36064)

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

Low