Lucene search

K
rockyRockylinux Product ErrataRLSA-2024:4351
HistoryJul 15, 2024 - 12:17 p.m.

virt:rhel and virt-devel:rhel security and bug fix update

2024-07-1512:17:49
Rockylinux Product Errata
errata.rockylinux.org
5
virt-rhel
security-update
bug-fix
libnbd
qemu-kvm
libvirt-python
swtpm
supermin
libvirt
sgabios
nbdkit
libtpms
libguestfs
seabios
netcf
perl-sys-virt
virt-v2v
libiscsi
libvirt-dbus
hivex
libguestfs-winsupport
cve-2024-4418
kvm

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

An update is available for libnbd, qemu-kvm, module.libvirt-python, module.swtpm, module.supermin, libvirt, module.qemu-kvm, module.sgabios, module.nbdkit, swtpm, libtpms, libguestfs, seabios, sgabios, module.libguestfs-winsupport, module.libguestfs, netcf, module.perl-Sys-Virt, module.virt-v2v, libiscsi, module.libnbd, virt-v2v, module.libvirt-dbus, module.libtpms, module.libvirt, module.netcf, hivex, supermin, libvirt-dbus, module.hivex, libguestfs-winsupport, module.libiscsi, module.seabios, perl-Sys-Virt, libvirt-python, nbdkit.
This update affects Rocky Linux 8.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix:

  • virt:libvirt: stack use-after-free in virNetClientIOEventLoop (CVE-2024-4418)

Bug fix:

  • virsh destroy with --graceful destroyed a paused guest (qemu process paused by SIGSTOP) (JIRA:Rocky Linux-36064)

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low