FlawAtlas
Search the atlas
ALSA-2021:3061 Not scored

Moderate: virt:rhel and virt-devel:rhel security and bug fix update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. Security Fix(es): * QEMU: msix: OOB access during mmio operations may lead to DoS (CVE-2020-13754) * hivex: Buffer overflow when provided invalid node key length (CVE-2021-3504) * QEMU: net: an assert failure via eth_get_gso_type (CVE-2020-27617) * QEMU: net: infinite loop in loopback mode may lead to stack overflow (CVE-2021-3416) * qemu: out-of-bound heap buffer access via an interrupt ID field (CVE-2021-20221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * cannot restart default network and firewalld: iptables: No chain/target/match by that name. (BZ#1958301) * RHEL8.4 Nightly[0322] - KVM guest fails to find zipl boot menu index (qemu-kvm) (BZ#1975679)

Exploit probability Not scored
Published August 10, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 nbdkit-xz-filter
AlmaLinux:8 python3-libnbd
AlmaLinux:8 sgabios
AlmaLinux:8 sgabios-bin
AlmaLinux:8 libguestfs-winsupport
AlmaLinux:8 nbdkit-example-plugins
AlmaLinux:8 supermin
AlmaLinux:8 python3-libvirt
AlmaLinux:8 nbdkit-basic-plugins
AlmaLinux:8 netcf-libs
AlmaLinux:8 perl-Sys-Virt
AlmaLinux:8 seabios-bin
AlmaLinux:8 nbdkit-ssh-plugin
AlmaLinux:8 nbdkit-basic-filters
AlmaLinux:8 nbdkit-bash-completion
AlmaLinux:8 libiscsi
AlmaLinux:8 nbdkit
AlmaLinux:8 nbdkit-devel
AlmaLinux:8 nbdfuse
AlmaLinux:8 nbdkit-python-plugin
AlmaLinux:8 libvirt-dbus
AlmaLinux:8 netcf
AlmaLinux:8 nbdkit-vddk-plugin
AlmaLinux:8 libnbd
AlmaLinux:8 nbdkit-server
AlmaLinux:8 libnbd-devel
AlmaLinux:8 seabios
AlmaLinux:8 libiscsi-devel
AlmaLinux:8 nbdkit-curl-plugin
AlmaLinux:8 libiscsi-utils
AlmaLinux:8 supermin-devel
AlmaLinux:8 netcf-devel
AlmaLinux:8 nbdkit-linuxdisk-plugin
AlmaLinux:8 nbdkit-gzip-plugin
AlmaLinux:8 seavgabios-bin

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2021:3061

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. Security Fix(es): * QEMU: msix: OOB access during mmio operations may lead to DoS (CVE-2020-13754) * hivex: Buffer overflow when provided invalid node key length (CVE-2021-3504) * QEMU: net: an assert failure via eth_get_gso_type (CVE-2020-27617) * QEMU: net: infinite loop in loopback mode may lead to stack overflow (CVE-2021-3416) * qemu: out-of-bound heap buffer access via an interrupt ID field (CVE-2021-20221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * cannot restart default network and firewalld: iptables: No chain/target/match by that name. (BZ#1958301) * RHEL8.4 Nightly[0322] - KVM guest fails to find zipl boot menu index (qemu-kvm) (BZ#1975679)

View original source

05 / REFERENCES

Further evidence