qemu-kvm-1.5.3-156.el7.1
エラータID: AXSA:2018-3085:04
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.
Security Fix(es):
* QEMU: cirrus: OOB access when updating VGA display (CVE-2018-7858)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Asianux would like to thank Ross Lagerwall (Citrix.com) for reporting this issue.
CVE-2018-7858
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
Update packages.
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
N/A
SRPMS
- qemu-kvm-1.5.3-156.el7.1.src.rpm
MD5: 5e8aa2bfc206f0f0a468c3660cfa9c37
SHA-256: ea016abfc40b39ced3028e85140dec2f4ab00a1d3e0a9b5e44113083c61e2d98
Size: 14.83 MB
Asianux Server 7 for x86_64
- qemu-img-1.5.3-156.el7.1.x86_64.rpm
MD5: 8b6a6075e9c20ef1c3a9950c56ad4e4e
SHA-256: af987b3cd2b4dd17e6453092a99a2fc0cc63bcd573bd29c629e0b7d636862954
Size: 689.75 kB - qemu-kvm-1.5.3-156.el7.1.x86_64.rpm
MD5: 14701f49fc663763c12c1a38582dbbe2
SHA-256: b1e161faa0052ef85952f2844e6747efe8d0d2d717c142b1fb258b4b68b01fc5
Size: 1.91 MB - qemu-kvm-common-1.5.3-156.el7.1.x86_64.rpm
MD5: a633c3aa22ce711b322cb261c1b1d86b
SHA-256: 5d9df4ba09f9ba4ad6768c7cc0632f66c6ccf9e2b9bbc81511091ba9be8cbd10
Size: 426.80 kB - qemu-kvm-tools-1.5.3-156.el7.1.x86_64.rpm
MD5: 4c7c2559836e98f141b73ff5c8d0d2a4
SHA-256: 4cbd9f79de77de16089cf224f8479cd2af9062f41b738813afdff70ddd8b362e
Size: 224.85 kB