[El-errata] ELSA-2017-0352 Important: Oracle Linux 6 qemu-kvm security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Mar 1 08:02:47 PST 2017


Oracle Linux Security Advisory ELSA-2017-0352

http://linux.oracle.com/errata/ELSA-2017-0352.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
qemu-guest-agent-0.12.1.2-2.491.el6_8.7.i686.rpm

x86_64:
qemu-guest-agent-0.12.1.2-2.491.el6_8.7.x86_64.rpm
qemu-img-0.12.1.2-2.491.el6_8.7.x86_64.rpm
qemu-kvm-0.12.1.2-2.491.el6_8.7.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.491.el6_8.7.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/qemu-kvm-0.12.1.2-2.491.el6_8.7.src.rpm



Description of changes:

[0.12.1.2-2.491.el6_8.7]
- kvm-cirrus-fix-patterncopy-checks.patch [bz#1420486 bz#1420488]
- kvm-Revert-cirrus-allow-zero-source-pitch-in-pattern-fil.patch 
[bz#1420486 bz#1420488]
- kvm-cirrus-add-blit_is_unsafe-call-to-cirrus_bitblt_cput.patch 
[bz#1420486 bz#1420488]
- Resolves: bz#1420486
   (EMBARGOED CVE-2017-2620 qemu-kvm: Qemu: display: cirrus: potential 
arbitrary code execution via cirrus_bitblt_cputovideo [rhel-6.8.z])
- Resolves: bz#1420488
   (EMBARGOED CVE-2017-2620 qemu-kvm-rhev: Qemu: display: cirrus: 
potential arbitrary code execution via cirrus_bitblt_cputovideo 
[rhel-6.8.z])





More information about the El-errata mailing list