Red Hat Security Advisory: qemu-kvm-rhev security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2013-4148 — qemu: virtio-net: buffer overflow on invalid state load CVE-2013-4149 — qemu: virtio-net: out-of-bounds buffer write on load CVE-2013-4150 — qemu: virtio-net: out-of-bounds buffer write on invalid state load CVE-2013-4151 — qemu: virtio: out-of-bounds buffer write on invalid state load CVE-2013-4527 — qemu: hpet: buffer overrun on invalid state load CVE-2013-4529 — qemu: hw/pci/pcie_aer.c: buffer overrun on invalid state load CVE-2013-4535 — qemu: virtio: insufficient validation of num_sg when mapping CVE-2013-4536 — qemu: virtio: insufficient validation of num_sg when mapping CVE-2013-4541 — qemu: usb: insufficient sanity checking of setup_index+setup_len in post_load CVE-2013-4542 — qemu: virtio-scsi: buffer overrun on invalid state load CVE-2013-6399 — qemu: virtio: buffer overrun on incoming migration CVE-2014-0182 — qemu: virtio: out-of-bounds buffer write on state load with invalid config_len CVE-2014-0222 — Qemu: qcow1: validate L2 table size to avoid integer overflows CVE-2014-0223 — Qemu: qcow1: validate image size to avoid out-of-bounds memory access CVE-2014-3461 — Qemu: usb: fix up post load checks
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2014:1268
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066334
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066353
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066361
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066384
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1066401
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1088986
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1096821
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1097216
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1097222
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1268.json