Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 37: 2022-22b1f8dae2 Moderate: QEMU Memory Corruption Issue

fedora
Calendar Grey December 14, 2022
Dist Fedora Esm H88
Check out the recent Fedora 37 update for QEMU, which tackles several security vulnerabilities, specifically concerning memory corruption and additional concerns.
hcd-xhci: infinite loop in xhci_ring_chain_length (CVE-2020-14394) ati-vga: out- of-bounds write in ati_2d_blt (CVE-2021-3638) acpi erst: memory corruption issues (CVE-2022-4172) q...

Summary

qemu is an open source virtualizer that provides hardware

emulation for the KVM hypervisor. qemu acts as a virtual

machine monitor together with the KVM kernel modules, and emulates the

hardware for a full system such as a PC and its associated peripherals.

hcd-xhci: infinite loop in xhci_ring_chain_length (CVE-2020-14394) ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) acpi erst: memory corruption

issues (CVE-2022-4172) qxl: qxl_phys2virt unsafe address translation

(CVE-2022-4144)

* Tue Dec 6 2022 Mauro Matteo Cascella - 2:7.0.0-12

- hcd-xhci: infinite loop in xhci_ring_chain_length (CVE-2020-14394) (rhbz#1908050)

- ati-vga: out-of-bounds write in ati_2d_blt (CVE-2021-3638) (rhbz#1979882)

- acpi erst: memory corruption issues (CVE-2022-4172) (rhbz#2149106)

- qxl: qxl_phys2virt unsafe address translation (CVE-2022-4144) (rhbz#2148542)

[ 1 ] Bug #1908050 - CVE-2020-14394 qemu: infinite loop in xhci_ring_chain_length() in hw/usb/hcd-xhci.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1908050

[ 2 ] Bug #1979882 - CVE-2021-3638 qemu: ati-vga: inconsistent check in ati_2d_blt() may lead to out-of-bounds write [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1979882

[ 3 ] Bug #2148542 - CVE-2022-4144 qemu: QXL: qxl_phys2virt unsafe address translation can lead to out-of-bounds read [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2148542

[ 4 ] Bug #2149106 - CVE-2022-4172 qemu: ACPI ERST: memory corruption issues in read_erst_record and write_erst_record [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2149106

su -c 'dnf upgrade --advisory FEDORA-2022-22b1f8dae2' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Product: Fedora 37
Version: 7.0.0
Release: 12.fc37
Summary: QEMU is a FAST! processor emulator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here