Red Hat Security Advisory: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2019-15890 — QEMU: Slirp: use-after-free during packet reassembly CVE-2019-20485 — libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent CVE-2020-1983 — QEMU: slirp: use-after-free in ip_reass() function in ip_input.c CVE-2020-10703 — libvirt: Potential denial of service via active pool without target path CVE-2020-14301 — libvirt: leak of sensitive cookie information via dumpxml CVE-2020-14339 — libvirt: leak of /dev/mapper/control into QEMU guests
🎯 Affected products200
- Red Hat CodeReady Linux Builder (v. 8)
- Red Hat Enterprise Linux AppStream (v. 8)
- SLOF-0:20191022-3.git899d9883.module+el8.3.0+6423+e4cb6418.noarch (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- SLOF-0:20191022-3.git899d9883.module+el8.3.0+6423+e4cb6418.src (virt-devel:rhel) as a component of Red Hat CodeReady Linux Builder (v. 8)
- SLOF-0:20191022-3.git899d9883.module+el8.3.0+6423+e4cb6418.src (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.aarch64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.i686 (virt-devel:rhel) as a component of Red Hat CodeReady Linux Builder (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.ppc64le (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.s390x (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.src (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.x86_64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debuginfo-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.aarch64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debuginfo-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.i686 (virt-devel:rhel) as a component of Red Hat CodeReady Linux Builder (v. 8)
- hivex-debuginfo-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.ppc64le (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debuginfo-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.s390x (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debuginfo-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.x86_64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debugsource-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.aarch64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debugsource-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.i686 (virt-devel:rhel) as a component of Red Hat CodeReady Linux Builder (v. 8)
- hivex-debugsource-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.ppc64le (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debugsource-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.s390x (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-debugsource-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.x86_64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-devel-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.aarch64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-devel-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.i686 (virt-devel:rhel) as a component of Red Hat CodeReady Linux Builder (v. 8)
- hivex-devel-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.ppc64le (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-devel-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.s390x (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- hivex-devel-0:1.3.18-20.module+el8.3.0+6423+e4cb6418.x86_64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libguestfs-1:1.40.2-25.module+el8.3.0+7421+642fe24f.aarch64 (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libguestfs-1:1.40.2-25.module+el8.3.0+7421+642fe24f.ppc64le (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libguestfs-1:1.40.2-25.module+el8.3.0+7421+642fe24f.s390x (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libguestfs-1:1.40.2-25.module+el8.3.0+7421+642fe24f.src (virt:rhel) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: This issue is mitigated on Red Hat Enterprise Linux if SELinux is in enforcing mode, which prevents the `/dev/mapper/control` file descriptor from being accessible by a guest user/process.
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2020:4676
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1518042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1664324
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717394
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1727865
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1749716
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1756946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1759849
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1763191
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1790189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1807057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1809740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1810193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1811539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816650
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1829825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1844296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1845459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848640
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1860069
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1867847
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4676.json