Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 22: 2015-5541 Critical Resource Limiting Issue in QEMU

fedora
Calendar Grey April 21, 2015
Dist Fedora Esm H88
The recent upgrade for QEMU on Fedora 22 tackles a critical resource allocation vulnerability within the VNC WebSockets decoder. This significant patch enhances security measures.
* Rebased to version 2.3.0-rc2 * Don't install ksm services as executable (bz #1192720) * Skip hanging tests on s390 (bz #1206057) * CVE-2015-1779 vnc: insufficient resource limiti...

Summary

QEMU is a generic and open source processor emulator which achieves a good

emulation speed by using dynamic translation. QEMU has two operating modes:

* Full system emulation. In this mode, QEMU emulates a full system (for

example a PC), including a processor and various peripherials. It can be

used to launch different Operating Systems without rebooting the PC or

to debug system code.

* User mode emulation. In this mode, QEMU can launch Linux processes compiled

for one CPU on another CPU.

As QEMU requires no host kernel patches to run, it is safe and easy to use.

Update Information:

* Rebased to version 2.3.0-rc2 * Don't install ksm services as executable (bz #1192720) * Skip hanging tests on s390 (bz #1206057) * CVE-2015-1779 vnc: insufficient resource limiting in VNC websockets decoder (bz #1205051, bz #1199572)

Change Log

References


[ 1 ] Bug #1199572 - CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder https://bugzilla.redhat.com/show_bug.cgi?id=1199572

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update qemu' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: qemu
Product: Fedora 22
Version: 2.3.0
Release: 0.3.rc2.fc22
Summary: QEMU is a FAST! processor emulator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here