qemu-kvm-1.5.3-141.el7.6

エラータID: AXSA:2018-2500:01

Release date: 
Sunday, January 7, 2018 - 19:51
Subject: 
qemu-kvm-1.5.3-141.el7.6
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm package provides the user-space component for running virtual machines that use KVM.

Security Fix(es):

* An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks. (CVE-2017-5715)

Note: This is the qemu-kvm side of the CVE-2017-5715 mitigation.

Asianux would like to thank Google Project Zero for reporting this issue.

CVE-2017-5715
Systems with microprocessors utilizing speculative execution and
indirect branch prediction may allow unauthorized disclosure of
information to an attacker with local user access via a side-channel
analysis.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. qemu-kvm-1.5.3-141.el7.6.src.rpm
    MD5: f1552f5795ae27221d92469a474292a6
    SHA-256: bd4d354049920627d8781bea51d029b6bc76632d0d178e593c01fda2f39efd23
    Size: 14.64 MB

Asianux Server 7 for x86_64
  1. qemu-img-1.5.3-141.el7.6.x86_64.rpm
    MD5: a71fd19ab6ab6fdc1fb5505832c157ea
    SHA-256: 160ba0493f929226e5796295d324a93b82d657ac8dcc90ab208fc9bfeb052b6f
    Size: 677.11 kB
  2. qemu-kvm-1.5.3-141.el7.6.x86_64.rpm
    MD5: 9a585910e6c970c4b9da7233593aed29
    SHA-256: 525a45d03b65899e66b3407bc55afd2197cd9b576048e0ea8f45979d5280b5c2
    Size: 1.89 MB
  3. qemu-kvm-common-1.5.3-141.el7.6.x86_64.rpm
    MD5: 928fff6f8f1f9868a0675aaf9cb53d31
    SHA-256: e936d0668eceda0fe9be3f6954a078bec994de411b35a0fe1b8e93b1dcc1f50b
    Size: 415.23 kB
  4. qemu-kvm-tools-1.5.3-141.el7.6.x86_64.rpm
    MD5: 864f7aab584c9c2fa26928825bd84bde
    SHA-256: 6776f7f051b352e137bec58b4a654b389190f10cdad511b0905d1684ac3edc40
    Size: 213.36 kB