CentOS 7 : qemu-kvm (CESA-2018:2462)
High Nessus Plugin ID 112021
SynopsisThe remote CentOS host is missing one or more security updates.
DescriptionAn update for qemu-kvm is now available for Red Hat Enterprise Linux
Red Hat Product Security has rated this update as having a security
impact of Important. A Common Vulnerability Scoring System (CVSS) base
score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.
Kernel-based Virtual Machine (KVM) is a full virtualization solution
for Linux on a variety of architectures. The qemu-kvm packages provide
the user-space component for running virtual machines that use KVM.
Security Fix(es) :
* QEMU: slirp: heap buffer overflow while reassembling fragmented
* QEMU: i386: multiboot OOB access while loading kernel image
For more details about the security issue(s), including the impact, a
CVSS score, and other related information, refer to the CVE page(s)
listed in the References section.
Red Hat would like to thank Jskz - Zero Day Initiative
(trendmicro.com) for reporting CVE-2018-11806 and Cyrille Chatras
(Orange.com) and CERT-CC (Orange.com) for reporting CVE-2018-7550.
Bug Fix(es) :
* Previously, live migrating a Windows guest in some cases caused the
guest to become unresponsive. This update ensures that Real-time Clock
(RTC) interrupts are not missed, which prevents the problem from
occurring. (BZ# 1596302)
SolutionUpdate the affected qemu-kvm packages.