Lucene search

K
redhatRedHatRHSA-2017:0352
HistoryMar 01, 2017 - 8:42 a.m.

(RHSA-2017:0352) Important: qemu-kvm security update

2017-03-0108:42:26
access.redhat.com
33

0.001 Low

EPSS

Percentile

51.1%

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process. (CVE-2017-2620)