For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing this update, shut down all running virtual machines. Once
all virtual machines have shut down, start them again for this update to
take effect.
KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on a variety of architectures. The qemu-kvm-rhev packages provide the
user-space component for running virtual machines that use KVM in
environments managed by Red Hat products.
Security Fix(es):
* QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams
(CVE-2018-11806)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
Red Hat would like to thank Jskz - Zero Day Initiative (trendmicro.com) for
reporting this issue.
https://access.redhat.com/security/cve/CVE-2018-11806 https://access.redhat.com/security/updates/classification#important
Red Hat OpenStack Platform 10.0:
Source:
qemu-kvm-rhev-2.10.0-21.el7_5.6.src.rpm
x86_64:
qemu-img-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-common-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-tools-rhev-2.10.0-21.el7_5.6.x86_64.rpm
Red Hat OpenStack Platform 12.0:
Source:
qemu-kvm-rhev-2.10.0-21.el7_5.6.src.rpm
ppc64le:
qemu-img-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-common-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-tools-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
x86_64:
qemu-img-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-common-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-rhev-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.6.x86_64.rpm
qemu-kvm-tools-rhev-2.10.0-21.el7_5.6.x86_64.rpm
Red Hat OpenStack Platform 13.0:
Source:
qemu-kvm-rhev-2.10.0-21.el7_5.6.src.rpm
ppc64le:
qemu-img-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-common-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.6.ppc64le.rpm
qemu-kvm-tools-rhev-2.10.0-21.el7_5.6.ppc64le.rpm
x86_64:
Read the Full Advisory
An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform8.0 (Liberty), Red Hat OpenStack Platform 9.0 (Mitaka), Red Hat OpenStackPlatform 10.0 (Newton), Red Hat OpenStack Platform 12.0 (Pike), and Red HatOpenStack Platform 13.0 (Queens).Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat OpenStack Platform 10.0 - x86_64
Red Hat OpenStack Platform 12.0 - ppc64le, x86_64
Red Hat OpenStack Platform 13.0 - ppc64le, x86_64
Red Hat OpenStack Platform 8.0 (Liberty) - x86_64
Red Hat OpenStack Platform 9.0 - x86_64
1586245 - CVE-2018-11806 QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams
Get the latest Linux and open source security news straight to your inbox.