Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.
Security Fix(es):
QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams (CVE-2018-11806)
QEMU: i386: multiboot OOB access while loading kernel image (CVE-2018-7550)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat would like to thank Jskz - Zero Day Initiative (trendmicro.com) for reporting CVE-2018-11806 and Cyrille Chatras (Orange.com) and CERT-CC (Orange.com) for reporting CVE-2018-7550.
Bug Fix(es):
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 7 | x86_64 | qemu-kvm-common | < 1.5.3-156.el7_5.5 | qemu-kvm-common-1.5.3-156.el7_5.5.x86_64.rpm |
RedHat | 7 | x86_64 | qemu-kvm-tools | < 1.5.3-156.el7_5.5 | qemu-kvm-tools-1.5.3-156.el7_5.5.x86_64.rpm |
RedHat | 7 | x86_64 | qemu-kvm | < 1.5.3-156.el7_5.5 | qemu-kvm-1.5.3-156.el7_5.5.x86_64.rpm |
RedHat | 7 | x86_64 | qemu-kvm-debuginfo | < 1.5.3-156.el7_5.5 | qemu-kvm-debuginfo-1.5.3-156.el7_5.5.x86_64.rpm |
RedHat | 7 | x86_64 | qemu-img | < 1.5.3-156.el7_5.5 | qemu-img-1.5.3-156.el7_5.5.x86_64.rpm |