QID 242861

Date Published: 2024-02-07

QID 242861: Red Hat Update for virt:rhel and virt-devel:rhel (RHSA-2024:0404)

Kernel-based virtual machine (kvm) offers a full virtualization solution for linux on numerous hardware platforms.
The virt:rhel module contains packages which provide user-space components used to run virtual machines using kvm.
The packages also provide apis for managing and interacting with the virtualized systems...Security Fix(es):

    qemu: vnc: improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service (cve-2023-3354).
    Qemu: hcd-ehci: dma reentrancy issue leads to use-after-free (cve-2021-3750).
    Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() (cve-2023-3019).
    Ntfs-3g: buffer overflow issue in ntfs-3g can cause code execution via crafted metadata in an ntfs image (cve-2022-40284).
Affected Products:
    Red Hat enterprise linux for x86_64 - extended update support 8.6 x86_64.
    Red hat enterprise linux server - aus 8.6 x86_64.
    Red hat enterprise linux for ibm z systems - extended update support 8.6 s390x.
    Red hat enterprise linux for power, little endian - extended update support 8.6 ppc64le.
    Red hat enterprise linux server - tus 8.6 x86_64.
    Red hat enterprise linux for arm 64 - extended update support 8.6 aarch64.
    Red hat enterprise linux server for power le - update services for sap solutions 8.6 ppc64le.
    Red hat enterprise linux for x86_64 - update services for sap solutions 8.6 x86_64.
    Red hat codeready linux builder for x86_64 - extended update support 8.6 x86_64.
    Red hat codeready linux builder for power, little endian - extended update support 8.6 ppc64le.
    Red hat codeready linux builder for ibm z systems - extended update support 8.6 s390x.
    Red hat codeready linux builder for arm 64 - extended update support 8.6 aarch64.
.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Red Hat security advisory RHSA-2024:0404 for updates and patch information.
    Vendor References

    CVEs related to QID 242861

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2024:0404 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2024:0404