Red Hat Product Errata RHSA-2018:0106 - Security Advisory
Issued:
2018-01-22
Updated:
2018-01-22

RHSA-2018:0106 - Security Advisory

Synopsis

Important: qemu-kvm security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm package provides the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks. (CVE-2017-5715)

Note: This is the qemu-kvm side of the CVE-2017-5715 mitigation.

Red Hat would like to thank Google Project Zero for reporting this issue.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux Server - AUS 6.4 x86_64

Fixes

  • BZ - 1519780 - CVE-2017-5715 hw: cpu: speculative execution branch target injection

CVEs

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 6.4

SRPM
qemu-kvm-0.12.1.2-2.355.el6_4.10.src.rpm SHA-256: d9c0c21882787a1aacd4979247d54d886dde4ac07edd47093ca74dcf594f7b70
x86_64
qemu-guest-agent-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: c65b1e5340d2a8c0790249f563ea5164e88d77298a26c21631fd29c1ed25ba8d
qemu-guest-agent-win32-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: 83b5c59d990e4b71b92347f6964c9d8e2d234c3d9374bc35aa0ceb731b1d09a6
qemu-img-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: 785ac773a6d47ce9f15ed74de5ae69e5f09b7d97ec7812da176ef8ab2d24ddc2
qemu-kvm-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: 916cbc488cd8ffd8b27e86f77d87546d776f6c0a9267a85e0aa94552afad6dfc
qemu-kvm-debuginfo-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: 6e871a20c891ed3d13532835bc53754eae2866cd3f95fcf115ae82794f52387a
qemu-kvm-debuginfo-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: 6e871a20c891ed3d13532835bc53754eae2866cd3f95fcf115ae82794f52387a
qemu-kvm-tools-0.12.1.2-2.355.el6_4.10.x86_64.rpm SHA-256: faf39af137457d724ba26814b81079d90612c4c3d1532156e9d2c7677bf2c0de

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.