FlawAtlas
Search the atlas
ALSA-2022:1759 Not scored

Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355) Security Fix(es): * QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748) * ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285) * ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286) * ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287) * ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289) * ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266) * ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267) * ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-2021-35268) * ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT (CVE-2021-35269) * ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() (CVE-2021-39251) * ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() (CVE-2021-39252) * ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() (CVE-2021-39253) * ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() (CVE-2021-39254) * ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute (CVE-2021-39255) * ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() (CVE-2021-39256) * ntfs-3g: Endless recursion from ntfs_attr_pwrite() triggered by an unallocated bitmap (CVE-2021-39257) * ntfs-3g: Out-of-bounds reads in ntfs_attr_find() and ntfs_external_attr_find() (CVE-2021-39258) * ntfs-3g: Out-of-bounds access in ntfs_inode_lookup_by_name() caused by an unsanitized attribute length (CVE-2021-39259) * ntfs-3g: Out-of-bounds access in ntfs_inode_sync_standard_information() (CVE-2021-39260) * ntfs-3g: Heap buffer overflow in ntfs_compressed_pwrite() (CVE-2021-39261) * ntfs-3g: Out-of-bounds access in ntfs_decompress() (CVE-2021-39262) * ntfs-3g: Heap buffer overflow in ntfs_get_attribute_value() caused by an unsanitized attribute (CVE-2021-39263) * libnbd: nbdcopy: missing error handling may create corrupted destination image (CVE-2022-0485) * hivex: stack overflow due to recursive call of _get_children() (CVE-2021-3622) * nbdkit: NBD_OPT_STRUCTURED_REPLY injection on STARTTLS (CVE-2021-3716) * libvirt: segmentation fault during VM shutdown can lead to vdsm hang (CVE-2021-3975) * QEMU: NULL pointer dereference in mirror_wait_on_conflicts() in block/mirror.c (CVE-2021-4145) * QEMU: NULL pointer dereference in pci_write() in hw/acpi/pcihp.c (CVE-2021-4158) * QEMU: block: fdc: null pointer dereference may lead to guest crash (CVE-2021-20196) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Exploit probability Not scored
Published May 10, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 virt-v2v
AlmaLinux:8 perl-Sys-Guestfs
AlmaLinux:8 ocaml-libguestfs-devel
AlmaLinux:8 nbdkit-xz-filter
AlmaLinux:8 libvirt-wireshark
AlmaLinux:8 libvirt-daemon
AlmaLinux:8 libvirt-daemon-driver-nodedev
AlmaLinux:8 libvirt-daemon-driver-secret
AlmaLinux:8 python3-libnbd
AlmaLinux:8 nbdkit-tmpdisk-plugin
AlmaLinux:8 sgabios
AlmaLinux:8 libvirt-nss
AlmaLinux:8 nbdkit-tar-plugin
AlmaLinux:8 ruby-hivex
AlmaLinux:8 ruby-libguestfs
AlmaLinux:8 libvirt-daemon-kvm
AlmaLinux:8 sgabios-bin
AlmaLinux:8 libguestfs-gfs2
AlmaLinux:8 qemu-kvm-block-ssh
AlmaLinux:8 libguestfs-winsupport
AlmaLinux:8 nbdkit-example-plugins
AlmaLinux:8 qemu-kvm-block-rbd
AlmaLinux:8 supermin
AlmaLinux:8 python3-libvirt
AlmaLinux:8 libvirt-libs
AlmaLinux:8 libguestfs-bash-completion
AlmaLinux:8 qemu-kvm
AlmaLinux:8 swtpm
AlmaLinux:8 libguestfs-appliance
AlmaLinux:8 libvirt
AlmaLinux:8 libguestfs-java-devel
AlmaLinux:8 perl-hivex
AlmaLinux:8 virt-v2v-bash-completion
AlmaLinux:8 libvirt-daemon-driver-storage-logical
AlmaLinux:8 nbdkit-basic-plugins
AlmaLinux:8 virt-v2v-man-pages-ja
AlmaLinux:8 libguestfs-javadoc
AlmaLinux:8 nbdkit-nbd-plugin
AlmaLinux:8 netcf-libs
AlmaLinux:8 swtpm-tools
AlmaLinux:8 perl-Sys-Virt
AlmaLinux:8 libvirt-daemon-driver-storage-scsi
AlmaLinux:8 python3-libguestfs
AlmaLinux:8 libguestfs-gobject-devel
AlmaLinux:8 libtpms-devel
AlmaLinux:8 qemu-kvm-docs
AlmaLinux:8 ocaml-libguestfs
AlmaLinux:8 seabios-bin
AlmaLinux:8 libguestfs-gobject
AlmaLinux:8 nbdkit-ssh-plugin
AlmaLinux:8 nbdkit-basic-filters
AlmaLinux:8 nbdkit-bash-completion
AlmaLinux:8 libvirt-lock-sanlock
AlmaLinux:8 libguestfs-rescue
AlmaLinux:8 libiscsi
AlmaLinux:8 python3-hivex
AlmaLinux:8 swtpm-devel
AlmaLinux:8 libvirt-daemon-driver-storage-gluster
AlmaLinux:8 swtpm-libs
AlmaLinux:8 ocaml-hivex-devel
AlmaLinux:8 ocaml-libnbd
AlmaLinux:8 nbdkit
AlmaLinux:8 nbdkit-devel
AlmaLinux:8 libvirt-daemon-driver-storage-rbd
AlmaLinux:8 lua-guestfs
AlmaLinux:8 libguestfs-tools
AlmaLinux:8 libvirt-daemon-config-network
AlmaLinux:8 nbdfuse
AlmaLinux:8 nbdkit-python-plugin
AlmaLinux:8 qemu-kvm-ui-spice
AlmaLinux:8 libguestfs-rsync
AlmaLinux:8 libvirt-dbus
AlmaLinux:8 libvirt-docs
AlmaLinux:8 qemu-img
AlmaLinux:8 libguestfs-tools-c
AlmaLinux:8 netcf
AlmaLinux:8 hivex-devel
AlmaLinux:8 qemu-kvm-block-iscsi
AlmaLinux:8 libvirt-daemon-driver-storage-disk
AlmaLinux:8 nbdkit-tar-filter
AlmaLinux:8 nbdkit-vddk-plugin
AlmaLinux:8 libvirt-daemon-driver-storage-iscsi
AlmaLinux:8 SLOF
AlmaLinux:8 libvirt-daemon-driver-nwfilter
AlmaLinux:8 libvirt-devel
AlmaLinux:8 qemu-kvm-ui-opengl
AlmaLinux:8 qemu-kvm-tests
AlmaLinux:8 libguestfs-man-pages-uk
AlmaLinux:8 libvirt-client
AlmaLinux:8 qemu-kvm-hw-usbredir
AlmaLinux:8 libnbd
AlmaLinux:8 libguestfs-man-pages-ja
AlmaLinux:8 libnbd-bash-completion
AlmaLinux:8 libvirt-daemon-driver-network
AlmaLinux:8 virt-dib
AlmaLinux:8 libvirt-daemon-driver-storage-core
AlmaLinux:8 hivex
AlmaLinux:8 ocaml-hivex
AlmaLinux:8 nbdkit-server
AlmaLinux:8 libnbd-devel
AlmaLinux:8 seabios
AlmaLinux:8 qemu-kvm-block-gluster
AlmaLinux:8 qemu-kvm-core
AlmaLinux:8 libvirt-daemon-driver-qemu
AlmaLinux:8 libvirt-daemon-config-nwfilter
AlmaLinux:8 libguestfs-xfs
AlmaLinux:8 libiscsi-devel
AlmaLinux:8 nbdkit-curl-plugin
AlmaLinux:8 libiscsi-utils
AlmaLinux:8 swtpm-tools-pkcs11
AlmaLinux:8 libvirt-daemon-driver-storage-iscsi-direct
AlmaLinux:8 nbdkit-gzip-filter
AlmaLinux:8 supermin-devel
AlmaLinux:8 libvirt-daemon-driver-storage
AlmaLinux:8 qemu-guest-agent
AlmaLinux:8 libtpms
AlmaLinux:8 libguestfs
AlmaLinux:8 libvirt-daemon-driver-storage-mpath
AlmaLinux:8 libguestfs-inspect-icons
AlmaLinux:8 ocaml-libnbd-devel
AlmaLinux:8 netcf-devel
AlmaLinux:8 libguestfs-java
AlmaLinux:8 qemu-kvm-common
AlmaLinux:8 nbdkit-linuxdisk-plugin
AlmaLinux:8 libvirt-daemon-driver-interface
AlmaLinux:8 nbdkit-gzip-plugin
AlmaLinux:8 qemu-kvm-block-curl
AlmaLinux:8 seavgabios-bin
AlmaLinux:8 virt-v2v-man-pages-uk
AlmaLinux:8 libguestfs-devel

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2022:1759

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems. The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355) Security Fix(es): * QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748) * ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285) * ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286) * ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287) * ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289) * ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266) * ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267) * ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-2021-35268) * ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT (CVE-2021-35269) * ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() (CVE-2021-39251) * ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() (CVE-2021-39252) * ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() (CVE-2021-39253) * ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() (CVE-2021-39254) * ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute (CVE-2021-39255) * ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() (CVE-2021-39256) * ntfs-3g: Endless recursion from ntfs_attr_pwrite() triggered by an unallocated bitmap (CVE-2021-39257) * ntfs-3g: Out-of-bounds reads in ntfs_attr_find() and ntfs_external_attr_find() (CVE-2021-39258) * ntfs-3g: Out-of-bounds access in ntfs_inode_lookup_by_name() caused by an unsanitized attribute length (CVE-2021-39259) * ntfs-3g: Out-of-bounds access in ntfs_inode_sync_standard_information() (CVE-2021-39260) * ntfs-3g: Heap buffer overflow in ntfs_compressed_pwrite() (CVE-2021-39261) * ntfs-3g: Out-of-bounds access in ntfs_decompress() (CVE-2021-39262) * ntfs-3g: Heap buffer overflow in ntfs_get_attribute_value() caused by an unsanitized attribute (CVE-2021-39263) * libnbd: nbdcopy: missing error handling may create corrupted destination image (CVE-2022-0485) * hivex: stack overflow due to recursive call of _get_children() (CVE-2021-3622) * nbdkit: NBD_OPT_STRUCTURED_REPLY injection on STARTTLS (CVE-2021-3716) * libvirt: segmentation fault during VM shutdown can lead to vdsm hang (CVE-2021-3975) * QEMU: NULL pointer dereference in mirror_wait_on_conflicts() in block/mirror.c (CVE-2021-4145) * QEMU: NULL pointer dereference in pci_write() in hw/acpi/pcihp.c (CVE-2021-4158) * QEMU: block: fdc: null pointer dereference may lead to guest crash (CVE-2021-20196) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

View original source

05 / REFERENCES

Further evidence