Lucene search

K
redhatRedHatRHSA-2019:1968
HistoryJul 30, 2019 - 10:30 a.m.

(RHSA-2019:1968) Important: qemu-kvm-rhev security and bug fix update

2019-07-3010:30:29
access.redhat.com
118

0.011 Low

EPSS

Percentile

84.2%

KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.

Security Fix(es):

  • CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob

  • CVE-2019-6778 QEMU: slirp: heap buffer overflow in tcp_em

This update fixes the following bug:

  • 1705364 RHV VM pauses when ‘dd’ issued inside guest to a direct lun configured as virtio-scsi with scsi-passthrough

Users of qemu-kvm are advised to upgrade to these updated packages. After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.