Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat 6.0: RHSA-2017:0981-01 Important: QEMU-KVM-RHEV Heap Overflow

red hat
Calendar Grey April 18, 2017
Scroller Redhat
A crucial security patch from Red Hat for qemu-kvm-rhev tackles possible code execution vulnerabilities within virtual environments.
An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.

Summary

KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.
Security Fix(es):
* Quick Emulator (QEMU), built with the Cirrus CLGD 54xx VGA Emulator and the VNC display driver support, is vulnerable to a heap buffer overflow issue. The issue could occur when a VNC client attempts to update its display after a VGA operation is performed by a guest. A privileged user/process inside guest could use this flaw to crash the QEMU process resulting in DoS or, potentially, leverage it to execute arbitrary code on the host with privileges of the QEMU process. (CVE-2016-9603)

References

https://access.redhat.com/security/cve/CVE-2016-9603 https://access.redhat.com/security/updates/classification#important

Package List

Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7:
Source: qemu-kvm-rhev-2.6.0-28.el7_3.9.src.rpm
x86_64: qemu-img-rhev-2.6.0-28.el7_3.9.x86_64.rpm qemu-kvm-common-rhev-2.6.0-28.el7_3.9.x86_64.rpm qemu-kvm-rhev-2.6.0-28.el7_3.9.x86_64.rpm qemu-kvm-rhev-debuginfo-2.6.0-28.el7_3.9.x86_64.rpm qemu-kvm-tools-rhev-2.6.0-28.el7_3.9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:0981-01
Product: Red Hat Enterprise Linux OpenStack Platform
Issue date: 2017-04-18

Topic

An update for qemu-kvm-rhev is now available for Red Hat Enterprise LinuxOpenStack Platform 6.0 (Juno) for RHEL 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 - x86_64

Bugs Fixed

1430056 - CVE-2016-9603 Qemu: cirrus: heap buffer overflow via vnc connection

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.