Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Oracle Linux 7 ELSA-2023-12368 Critical: QEMU Security Advisory

oracle
Calendar Grey June 12, 2023
Oracle Linux Logo Esm H88
Key announcement for Oracle Linux 7 regarding qemu security risks, including specifics on software updates and resolutions.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[15:4.2.1-26.el7] - migration: check magic value for deciding the mapping of channels (manish.mishra) [Orabug: 34735462] - io: Add support for MSG_PEEK for socket channel (manish.mishra) [Orabug: 34735462] - migration: Move channel setup out of postcopy_try_recover() (Peter Xu) [Orabug: 34735462] - vdpa: commit all host notifier MRs in a single MR transaction (Longpeng (Mike)) [Orabug: 35252234] - vhost: configure all host notifiers in a single MR transaction (Longpeng (Mike)) [Orabug: 35252234] - vhost: simplify vhost_dev_enable_notifiers (Longpeng (Mike)) [Orabug: 35252234] - pcie: Do not update hotplugged device power in RUN_STATE_INMIGRATE state (Annie Li) [Orabug: 35055290] - qga/win32: Use rundll for VSS installation (Konstantin Kostiuk) [Orabug: 35206108] {CVE-2023-0664} - qga/win32: Remove change action from MSI installer (Konstantin Kostiuk) [Orabug: 35206108] {CVE-2023-0664} - hw/display/qxl: Assert memory slot fits in preallocated MemoryRegion (Philippe Mathi...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//qemu-4.2.1-26.el7.src.rpm

x86_64

aarch64

ivshmem-tools-4.2.1-26.el7.aarch64.rpm qemu-4.2.1-26.el7.aarch64.rpm qemu-block-gluster-4.2.1-26.el7.aarch64.rpm qemu-block-iscsi-4.2.1-26.el7.aarch64.rpm qemu-block-rbd-4.2.1-26.el7.aarch64.rpm qemu-common-4.2.1-26.el7.aarch64.rpm qemu-img-4.2.1-26.el7.aarch64.rpm qemu-kvm-4.2.1-26.el7.aarch64.rpm qemu-kvm-core-4.2.1-26.el7.aarch64.rpm qemu-system-aarch64-4.2.1-26.el7.aarch64.rpm qemu-system-aarch64-core-4.2.1-26.el7.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2022-4144 CVE-2023-0664

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here