Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 36: Critical Advisory FEDORA-2023-c8a60f6f80 Out-Of-Bounds Issues

fedora
Calendar Grey January 19, 2023
Dist Fedora Esm H88
Major enhancements to QEMU in Fedora 36, focusing on crucial security vulnerabilities and improving the accuracy of device emulation.
ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) (rhbz#1979882) qxl: qxl_phys2virt unsafe address translation (CVE-2022-4144) (rhbz#2148542) linux- user: default to -cpu ...

Summary

qemu is an open source virtualizer that provides hardware

emulation for the KVM hypervisor. qemu acts as a virtual

machine monitor together with the KVM kernel modules, and emulates the

hardware for a full system such as a PC and its associated peripherals.

ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) (rhbz#1979882) qxl:

qxl_phys2virt unsafe address translation (CVE-2022-4144) (rhbz#2148542) linux-user: default to -cpu max (rhbz#2121700)

* Tue Jan 3 2023 Mauro Matteo Cascella - 2:6.2.0-17

- ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) (rhbz#1979882)

- qxl: qxl_phys2virt unsafe address translation (CVE-2022-4144) (rhbz#2148542)

- linux-user: default to -cpu max (rhbz#2121700)

[ 1 ] Bug #1979882 - CVE-2021-3638 qemu: ati-vga: inconsistent check in ati_2d_blt() may lead to out-of-bounds write [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1979882

[ 2 ] Bug #2121700 - qemu-x86_64-static cannot run el9 binaries by default

https://bugzilla.redhat.com/show_bug.cgi?id=2121700

[ 3 ] Bug #2148542 - CVE-2022-4144 qemu: QXL: qxl_phys2virt unsafe address translation can lead to out-of-bounds read [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2148542

su -c 'dnf upgrade --advisory FEDORA-2023-c8a60f6f80' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 6.2.0
Release: 17.fc36
Summary: QEMU is a FAST! processor emulator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here