FlawAtlas
Search the atlas
ALSA-2020:4676 Not scored

Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296) Security Fix(es): * libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339) * QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890) * libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485) * QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983) * libvirt: Potential denial of service via active pool without target path (CVE-2020-10703) * libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Exploit probability Not scored
Published November 3, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 ocaml-libguestfs-devel
AlmaLinux:8 nbdkit-xz-filter
AlmaLinux:8 libvirt-daemon
AlmaLinux:8 libvirt-daemon-driver-nodedev
AlmaLinux:8 libvirt-daemon-driver-secret
AlmaLinux:8 python3-libnbd
AlmaLinux:8 sgabios
AlmaLinux:8 libvirt-nss
AlmaLinux:8 ruby-hivex
AlmaLinux:8 sgabios-bin
AlmaLinux:8 libguestfs-winsupport
AlmaLinux:8 nbdkit-example-plugins
AlmaLinux:8 supermin
AlmaLinux:8 python3-libvirt
AlmaLinux:8 libvirt-libs
AlmaLinux:8 libvirt
AlmaLinux:8 perl-hivex
AlmaLinux:8 libvirt-daemon-driver-storage-logical
AlmaLinux:8 nbdkit-basic-plugins
AlmaLinux:8 netcf-libs
AlmaLinux:8 perl-Sys-Virt
AlmaLinux:8 libvirt-daemon-driver-storage-scsi
AlmaLinux:8 ocaml-libguestfs
AlmaLinux:8 seabios-bin
AlmaLinux:8 nbdkit-ssh-plugin
AlmaLinux:8 nbdkit-basic-filters
AlmaLinux:8 nbdkit-bash-completion
AlmaLinux:8 libvirt-daemon-driver-storage-iscsi
AlmaLinux:8 libiscsi
AlmaLinux:8 python3-hivex
AlmaLinux:8 libvirt-bash-completion
AlmaLinux:8 ocaml-hivex-devel
AlmaLinux:8 ocaml-libnbd
AlmaLinux:8 nbdkit
AlmaLinux:8 nbdkit-devel
AlmaLinux:8 libvirt-daemon-driver-storage-rbd
AlmaLinux:8 libvirt-daemon-config-network
AlmaLinux:8 nbdfuse
AlmaLinux:8 nbdkit-python-plugin
AlmaLinux:8 libvirt-dbus
AlmaLinux:8 libvirt-docs
AlmaLinux:8 netcf
AlmaLinux:8 hivex-devel
AlmaLinux:8 libvirt-daemon-driver-storage-disk
AlmaLinux:8 nbdkit-vddk-plugin
AlmaLinux:8 libvirt-daemon-driver-nwfilter
AlmaLinux:8 libvirt-devel
AlmaLinux:8 libvirt-client
AlmaLinux:8 libnbd
AlmaLinux:8 libvirt-daemon-driver-network
AlmaLinux:8 libvirt-daemon-driver-storage-core
AlmaLinux:8 hivex
AlmaLinux:8 ocaml-hivex
AlmaLinux:8 nbdkit-server
AlmaLinux:8 libnbd-devel
AlmaLinux:8 seabios
AlmaLinux:8 libvirt-daemon-config-nwfilter
AlmaLinux:8 libiscsi-devel
AlmaLinux:8 nbdkit-curl-plugin
AlmaLinux:8 libiscsi-utils
AlmaLinux:8 libvirt-daemon-driver-storage-iscsi-direct
AlmaLinux:8 supermin-devel
AlmaLinux:8 libvirt-daemon-driver-storage
AlmaLinux:8 libvirt-daemon-driver-storage-mpath
AlmaLinux:8 ocaml-libnbd-devel
AlmaLinux:8 netcf-devel
AlmaLinux:8 nbdkit-linuxdisk-plugin
AlmaLinux:8 libvirt-daemon-driver-interface
AlmaLinux:8 nbdkit-gzip-plugin
AlmaLinux:8 seavgabios-bin
AlmaLinux:8 libvirt-admin

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2020:4676

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296) Security Fix(es): * libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339) * QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890) * libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485) * QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983) * libvirt: Potential denial of service via active pool without target path (CVE-2020-10703) * libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

View original source

05 / REFERENCES

Further evidence