Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Oracle Linux 7 ELSA-2022-9669 Critical: QEMU Stability Update

oracle
Calendar Grey August 2, 2022
Oracle Linux Logo Esm H88
Key Oracle Linux 7 security notice ELSA-2022-9670 brings enhancements to qemu packages, fixing severe vulnerabilities.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

Summary

[15:4.2.1-18.el7] - block: introduce max_hw_iov for use in scsi-generic (Paolo Bonzini) [Orabug: 33785156] - file-posix: try BLKSECTGET on block devices too, do not round to power of 2 (Paolo Bonzini) [Orabug: 33785156] - block: add max_hw_transfer to BlockLimits (Paolo Bonzini) [Orabug: 33785156] - block-backend: align max_transfer to request alignment (Paolo Bonzini) [Orabug: 33785156] - osdep: provide ROUND_DOWN macro (Paolo Bonzini) [Orabug: 33785156] - scsi-generic: pass max_segments via max_iov field in BlockLimits (Paolo Bonzini) [Orabug: 33785156] - file-posix: fix max_iov for /dev/sg devices (Paolo Bonzini) [Orabug: 33785156] - display/qxl-render: fix race condition in qxl_cursor (CVE-2021-4207) (Mauro Matteo Cascella) [Orabug: 34049511] {CVE-2021-4207} - ui/cursor: fix integer overflow in cursor_alloc (CVE-2021-4206) (Mauro Matteo Cascella) [Orabug: 34049509] {CVE-2021-4206} - hw/block/fdc: Prevent end-of-track overrun (CVE-2021-3507) (Philippe Mathieu-Daud=E9)...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates/qemu-4.2.1-18.el7.src.rpm

x86_64

aarch64

ivshmem-tools-4.2.1-18.el7.aarch64.rpm qemu-4.2.1-18.el7.aarch64.rpm qemu-block-gluster-4.2.1-18.el7.aarch64.rpm qemu-block-iscsi-4.2.1-18.el7.aarch64.rpm qemu-block-rbd-4.2.1-18.el7.aarch64.rpm qemu-common-4.2.1-18.el7.aarch64.rpm qemu-img-4.2.1-18.el7.aarch64.rpm qemu-kvm-4.2.1-18.el7.aarch64.rpm qemu-kvm-core-4.2.1-18.el7.aarch64.rpm qemu-system-aarch64-4.2.1-18.el7.aarch64.rpm qemu-system-aarch64-core-4.2.1-18.el7.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2021-3507 CVE-2021-4206 CVE-2021-4207

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here