qemu-kvm-1.5.3-156.el7.1

エラータID: AXSA:2018-3085:04

Release date: 
Tuesday, May 15, 2018 - 13:56
Subject: 
qemu-kvm-1.5.3-156.el7.1
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

* QEMU: cirrus: OOB access when updating VGA display (CVE-2018-7858)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Asianux would like to thank Ross Lagerwall (Citrix.com) for reporting this issue.

CVE-2018-7858
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. qemu-kvm-1.5.3-156.el7.1.src.rpm
    MD5: 5e8aa2bfc206f0f0a468c3660cfa9c37
    SHA-256: ea016abfc40b39ced3028e85140dec2f4ab00a1d3e0a9b5e44113083c61e2d98
    Size: 14.83 MB

Asianux Server 7 for x86_64
  1. qemu-img-1.5.3-156.el7.1.x86_64.rpm
    MD5: 8b6a6075e9c20ef1c3a9950c56ad4e4e
    SHA-256: af987b3cd2b4dd17e6453092a99a2fc0cc63bcd573bd29c629e0b7d636862954
    Size: 689.75 kB
  2. qemu-kvm-1.5.3-156.el7.1.x86_64.rpm
    MD5: 14701f49fc663763c12c1a38582dbbe2
    SHA-256: b1e161faa0052ef85952f2844e6747efe8d0d2d717c142b1fb258b4b68b01fc5
    Size: 1.91 MB
  3. qemu-kvm-common-1.5.3-156.el7.1.x86_64.rpm
    MD5: a633c3aa22ce711b322cb261c1b1d86b
    SHA-256: 5d9df4ba09f9ba4ad6768c7cc0632f66c6ccf9e2b9bbc81511091ba9be8cbd10
    Size: 426.80 kB
  4. qemu-kvm-tools-1.5.3-156.el7.1.x86_64.rpm
    MD5: 4c7c2559836e98f141b73ff5c8d0d2a4
    SHA-256: 4cbd9f79de77de16089cf224f8479cd2af9062f41b738813afdff70ddd8b362e
    Size: 224.85 kB