qemu-kvm (SL6)

Synopsis: Moderate: qemu-kvm security update
Advisory ID: SLSA-2016:1585-1
Issue Date: 2016-08-09
CVE Numbers: CVE-2016-5403

Security Fix(es):

* Quick emulator(Qemu) built with the virtio framework is vulnerable to an
unbounded memory allocation issue. It was found that a malicious guest
user could submit more requests than the virtqueue size permits.
Processing a request allocates a VirtQueueElement and therefore causes
unbounded memory allocation on the host controlled by the guest.
(CVE-2016-5403)

SL6
x86_64
qemu-guest-agent-0.12.1.2-2.491.el6_8.3.x86_64.rpm
qemu-img-0.12.1.2-2.491.el6_8.3.x86_64.rpm
qemu-kvm-0.12.1.2-2.491.el6_8.3.x86_64.rpm
qemu-kvm-debuginfo-0.12.1.2-2.491.el6_8.3.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.491.el6_8.3.x86_64.rpm
i386
qemu-guest-agent-0.12.1.2-2.491.el6_8.3.i686.rpm
qemu-kvm-debuginfo-0.12.1.2-2.491.el6_8.3.i686.rpm

Additionally, releases 6.0 – 6.7 required the following packages
already available in SL6.8 for dependencies:
x86_64
glusterfs-3.7.5-19.el6.x86_64.rpm
glusterfs-api-3.7.5-19.el6.x86_64.rpm
glusterfs-api-devel-3.7.5-19.el6.x86_64.rpm
glusterfs-cli-3.7.5-19.el6.x86_64.rpm
glusterfs-client-xlators-3.7.5-19.el6.x86_64.rpm
glusterfs-devel-3.7.5-19.el6.x86_64.rpm
glusterfs-fuse-3.7.5-19.el6.x86_64.rpm
glusterfs-ganesha-3.7.5-19.el6.x86_64.rpm
glusterfs-libs-3.7.5-19.el6.x86_64.rpm
glusterfs-rdma-3.7.5-19.el6.x86_64.rpm
glusterfs-resource-agents-3.7.5-19.el6.noarch.rpm
glusterfs-server-3.7.5-19.el6.x86_64.rpm
nfs-ganesha-2.2.0-12.el6.x86_64.rpm
nfs-ganesha-gluster-2.2.0-12.el6.x86_64.rpm
python-argparse-1.2.1-2.1.el6.noarch.rpm
pyxattr-0.5.0-1.el6.x86_64.rpm
userspace-rcu-0.7.9-2.el6rhs.x86_64.rpm
userspace-rcu-devel-0.7.9-2.el6rhs.x86_64.rpm

– Scientific Linux Development Team