CentOS 7 : qemu-kvm (CESA-2018:2462)
High Nessus Plugin ID 112021
SynopsisThe remote CentOS host is missing one or more security updates.
DescriptionAn update for qemu-kvm is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.
Security Fix(es) :
* QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams (CVE-2018-11806)
* QEMU: i386: multiboot OOB access while loading kernel image (CVE-2018-7550)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat would like to thank Jskz - Zero Day Initiative (trendmicro.com) for reporting CVE-2018-11806 and Cyrille Chatras (Orange.com) and CERT-CC (Orange.com) for reporting CVE-2018-7550.
Bug Fix(es) :
* Previously, live migrating a Windows guest in some cases caused the guest to become unresponsive. This update ensures that Real-time Clock (RTC) interrupts are not missed, which prevents the problem from occurring. (BZ# 1596302)
SolutionUpdate the affected qemu-kvm packages.