[El-errata] ELSA-2015-1833 Moderate: Oracle Linux 6 qemu-kvm security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Sep 22 23:23:50 PDT 2015


Oracle Linux Security Advisory ELSA-2015-1833

http://linux.oracle.com/errata/ELSA-2015-1833.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
qemu-guest-agent-0.12.1.2-2.479.el6_7.1.i686.rpm

x86_64:
qemu-guest-agent-0.12.1.2-2.479.el6_7.1.x86_64.rpm
qemu-img-0.12.1.2-2.479.el6_7.1.x86_64.rpm
qemu-kvm-0.12.1.2-2.479.el6_7.1.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.479.el6_7.1.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/qemu-kvm-0.12.1.2-2.479.el6_7.1.src.rpm



Description of changes:

[0.12.1.2-2.479.el6_7.1]
- kvm-rtl8139-avoid-nested-ifs-in-IP-header-parsing-CVE-20.patch 
[bz#1248761]
- kvm-rtl8139-drop-tautologous-if-ip-.-statement-CVE-2015-.patch 
[bz#1248761]
- kvm-rtl8139-skip-offload-on-short-Ethernet-IP-header-CVE.patch 
[bz#1248761]
- kvm-rtl8139-check-IP-Header-Length-field-CVE-2015-5165.patch [bz#1248761]
- kvm-rtl8139-check-IP-Total-Length-field-CVE-2015-5165.patch [bz#1248761]
- kvm-rtl8139-skip-offload-on-short-TCP-header-CVE-2015-51.patch 
[bz#1248761]
- kvm-rtl8139-check-TCP-Data-Offset-field-CVE-2015-5165.patch [bz#1248761]
- Resolves: bz#1248761
   (CVE-2015-5165 qemu-kvm: Qemu: rtl8139 uninitialized heap memory 
information leakage to guest [rhel-6.7.z])





More information about the El-errata mailing list