[El-errata] ELSA-2017-0396 Important: Oracle Linux 7 qemu-kvm security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Mar 2 18:42:39 PST 2017


Oracle Linux Security Advisory ELSA-2017-0396

http://linux.oracle.com/errata/ELSA-2017-0396.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
qemu-img-1.5.3-126.el7_3.5.x86_64.rpm
qemu-kvm-1.5.3-126.el7_3.5.x86_64.rpm
qemu-kvm-common-1.5.3-126.el7_3.5.x86_64.rpm
qemu-kvm-tools-1.5.3-126.el7_3.5.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/qemu-kvm-1.5.3-126.el7_3.5.src.rpm



Description of changes:

[1.5.3-126.el7_3.5]
- kvm-cirrus-fix-patterncopy-checks.patch [bz#1420490]
- kvm-Revert-cirrus-allow-zero-source-pitch-in-pattern-fil.patch 
[bz#1420490]
- kvm-cirrus-add-blit_is_unsafe-call-to-cirrus_bitblt_cput.patch 
[bz#1420490]
- Resolves: bz#1420490
   (EMBARGOED CVE-2017-2620 qemu-kvm: Qemu: display: cirrus: potential 
arbitrary code execution via cirrus_bitblt_cputovideo [rhel-7.3.z])

[1.5.3-126.el7_3.4]
- kvm-virtio-blk-Release-s-rq-queue-at-system_reset.patch [bz#1420049]
- kvm-cirrus_vga-fix-off-by-one-in-blit_region_is_unsafe.patch [bz#1418232]
- kvm-display-cirrus-check-vga-bits-per-pixel-bpp-value.patch [bz#1418232]
- kvm-display-cirrus-ignore-source-pitch-value-as-needed-i.patch 
[bz#1418232]
- kvm-cirrus-handle-negative-pitch-in-cirrus_invalidate_re.patch 
[bz#1418232]
- kvm-cirrus-allow-zero-source-pitch-in-pattern-fill-rops.patch [bz#1418232]
- kvm-cirrus-fix-blit-address-mask-handling.patch [bz#1418232]
- kvm-cirrus-fix-oob-access-issue-CVE-2017-2615.patch [bz#1418232]
- Resolves: bz#1418232
   (CVE-2017-2615 qemu-kvm: Qemu: display: cirrus: oob access while 
doing bitblt copy backward mode [rhel-7.3.z])
- Resolves: bz#1420049
   (system_reset should clear pending request for error (virtio-blk))





More information about the El-errata mailing list