[Oraclevm-errata] OVMSA-2017-0047 Important: Oracle VM 3.4 qemu-kvm security update
Errata Announcements for Oracle VM
oraclevm-errata at oss.oracle.com
Wed Mar 1 14:19:30 PST 2017
Oracle VM Security Advisory OVMSA-2017-0047
The following updated rpms for Oracle VM 3.4 have been uploaded to the
Unbreakable Linux Network:
x86_64:
qemu-img-0.12.1.2-2.491.el6_8.7.x86_64.rpm
SRPMS:
http://oss.oracle.com/oraclevm/server/3.4/SRPMS-updates/qemu-kvm-0.12.1.2-2.491.el6_8.7.src.rpm
Description of changes:
[0.12.1.2-2.491.el6_8.7]
- kvm-cirrus-fix-patterncopy-checks.patch [bz#1420486 bz#1420488]
- kvm-Revert-cirrus-allow-zero-source-pitch-in-pattern-fil.patch
[bz#1420486 bz#1420488]
- kvm-cirrus-add-blit_is_unsafe-call-to-cirrus_bitblt_cput.patch
[bz#1420486 bz#1420488]
- Resolves: bz#1420486
(EMBARGOED CVE-2017-2620 qemu-kvm: Qemu: display: cirrus: potential
arbitrary code execution via cirrus_bitblt_cputovideo [rhel-6.8.z])
- Resolves: bz#1420488
(EMBARGOED CVE-2017-2620 qemu-kvm-rhev: Qemu: display: cirrus:
potential arbitrary code execution via cirrus_bitblt_cputovideo
[rhel-6.8.z])
More information about the Oraclevm-errata
mailing list