Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Scientific Linux: Important qemu-kvm Update Addresses Execution Risks

Scientific Large Esm H500
Important: qemu-kvm security, bug fix, and enhancement update
Date: Wed, 6 Jul 2011 14:11:55 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Important: qemu-kvm on SL6.x x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 
MIME-Version: 1.0

Synopsis:	Important: qemu-kvm security, bug fix, and enhancement update
Issue date:	2011-05-19
CVE Names:	CVE-2011-1750 CVE-2011-1751

KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space
component for running virtual machines using KVM.

It was found that the virtio-blk driver in qemu-kvm did not properly
validate read and write requests from guests. A privileged guest user
could use this flaw to crash the guest or, possibly, execute arbitrary
code on the host. (CVE-2011-1750)

It was found that the PIIX4 Power Management emulation layer in qemu-kvm
did not properly check for hot plug eligibility during device removals.
A privileged guest user could use this flaw to crash the guest or,
possibly, execute arbitrary code on the host. (CVE-2011-1751)

This update also fixes several bugs and adds various enhancements.

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues, and fix the bugs and
add the enhancements.

After installing this update, shut down all running virtual machines.
Once all virtual machines have shut down, start them again for this
update to take effect.

SL 6.x

 SRPMS:
qemu-kvm-0.12.1.2-2.160.el6.src.rpm
 x86_64:
qemu-img-0.12.1.2-2.160.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.160.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.160.el6.x86_64.rpm
 Dependancies:
spice-protocol-0.8.0-1.el6.noarch.rpm
spice-server-0.8.0-1.el6.x86_64.rpm
spice-server-devel-0.8.0-1.el6.x86_64.rpm
vgabios-0.6b-3.6.el6.noarch.rpm

- Scientific Linux Development Team
Your message here