Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259
KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.
It was found that qemu-kvm did not properly drop supplemental group
privileges when the root user started guests from the command line
("/usr/libexec/qemu-kvm") with the "-runas" option. A qemu-kvm process
started this way could use this flaw to gain access to files on the host
that are accessible to the supplementary groups and not accessible to the
primary group. (CVE-2011-2527)
Note: This issue only affected qemu-kvm when it was started directly from
the command line. It did not affect the Red Hat Enterprise Virtualization
platform or applications that start qemu-kvm via libvirt, such as the
Virtual Machine Manager (virt-manager).
This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.
All users of qemu-kvm are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements. After installing this update, shut down all running virtual
machines. Once all virtual machines have shut down, start them again for
this update to take effect.
https://access.redhat.com/security/cve/CVE-2011-2527 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/search/
Red Hat Enterprise Linux Desktop (v. 6):
Source:
x86_64:
qemu-img-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-debuginfo-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.209.el6.x86_64.rpm
Red Hat Enterprise Linux HPC Node (v. 6):
Source:
x86_64:
qemu-img-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-debuginfo-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.209.el6.x86_64.rpm
Red Hat Enterprise Linux Server (v. 6):
Source:
x86_64:
qemu-img-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-debuginfo-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.209.el6.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 6):
Source:
x86_64:
qemu-img-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-debuginfo-0.12.1.2-2.209.el6.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.209.el6.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package
Updated qemu-kvm packages that fix one security issue, multiple bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available from the CVE link inthe References section.
Red Hat Enterprise Linux Desktop (v. 6) - x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - x86_64
Red Hat Enterprise Linux Server (v. 6) - x86_64
Red Hat Enterprise Linux Workstation (v. 6) - x86_64
561414 - Writes to virtual usb-storage produce I/O errors599306 - Some strange behaviors on key's appearance viewed by using vnc
609342 - rhel3u9 install can't find package after inserting second CD, but install can continue
621482 - [RFE] Be able to get progress from qemu-img
624983 - QEMU should support the newer set of MSRs for kvmclock
627585 - Improve error messages for bad options in -drive and -device
633370 - [6.1 FEAT] Enhance QED image format to support streaming from remote systems
633380 - [6.2 FEAT] Include QED image format for KVM guests
645351 - Add support for USB 2.0 (EHCI) to QEMU
655719 - no error pops when change cd to non-exist file
656779 - Core dumped when hot plug/un-plug virtio serial port to the same chardev
658467 - kvm clock breaks migration result stability - for unit test propose
669581 - Migration Never end while Use firewall reject migration tcp port
676982 - RFE: no qmp command for live snapshot
678729 - Hotplug VF/PF with invalid addr value leading to qemu-kvm process quit with core dump
678731 - Update qemu-kvm -device pci-assign,? properties
680378 - no error message when loading zero size internal snapshot
681736 - Guest->Host communication stops for other ports after one port is unplugged
682227 - qemu-kvm doesn't exit when binding to specified port fails
693645 - RFE: add spice option to enable/disable copy paste
694373 - ballooning value reset to original value after setting a negative number
Get the latest Linux and open source security news straight to your inbox.