Low: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Related Vulnerabilities: CVE-2021-3507   CVE-2022-0897   CVE-2022-2211   CVE-2022-23645  

Synopsis

Low: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0). (BZ#2066828)

Security Fix(es):

  • QEMU: fdc: heap buffer overflow in DMA read data transfers (CVE-2021-3507)
  • libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service (CVE-2022-0897)
  • libguestfs: Buffer overflow in get_keys leads to DoS (CVE-2022-2211)
  • swtpm: Unchecked header size indicator against expected size (CVE-2022-23645)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x

Fixes

  • BZ - 1519071 - Fail to rebuild the reference count tables of qcow2 image on host block devices (e.g. LVs)
  • BZ - 1851227 - When doing a cpu-baseline between skylake and cascadelake, cascadelake is selected as baseline.
  • BZ - 1951118 - CVE-2021-3507 QEMU: fdc: heap buffer overflow in DMA read data transfers
  • BZ - 1985827 - Start or remove VM failure even v2v has already finished
  • BZ - 2028823 - assertion failed at parse_ova.ml when ova directory ends with '/'
  • BZ - 2029980 - Failed assertion in IDE emulation with Ceph backend
  • BZ - 2051332 - supermin should ignore +debug kernels when choosing a kernel to boot
  • BZ - 2056491 - CVE-2022-23645 swtpm: Unchecked header size indicator against expected size
  • BZ - 2060843 - [virtual network][vDPA] qemu crash after hot unplug vdpa device [rhel-8.7.0]
  • BZ - 2062610 - Do operation to disk will hang in the guest of target host after hotplugging and migrating [rhel-8.7.0]
  • BZ - 2062611 - Guest can not start with SLIC acpi table [rhel-8.7.0]
  • BZ - 2063883 - CVE-2022-0897 libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service
  • BZ - 2066828 - rebase seabios to 1.16 release
  • BZ - 2067118 - qemu crash after execute blockdev-reopen with iothread
  • BZ - 2067126 - Allow memory prealloc from multiple threads
  • BZ - 2069946 - PXE boot crash qemu when using multiqueue vDPA
  • BZ - 2070417 - Windows guest hangs after updating and restarting from the guest OS [rhel-8.7.0]
  • BZ - 2071070 - s390x/css: fix PMCW invalid mask
  • BZ - 2072049 - Pull MSG_ZEROCOPY on QEMU Live Migration Patches into RHEL 8
  • BZ - 2072377 - Fix build warnings that occur when installing the keymap files
  • BZ - 2072932 - Qemu coredump when refreshing block limits on an actively used iothread block device [rhel.8.7]
  • BZ - 2073012 - Guest whose os is installed multiple disks but boot partition is installed on single disk can't boot into OS on RHEL 8 [rhel-8.7.0]
  • BZ - 2075424 - virt-customize fails with "error: Fatal glibc error: CPU does not support x86-64-v2" with TCG mode
  • BZ - 2079582 - [libvirt] virtiofsd: Allow option --thread-pool-size=X
  • BZ - 2083884 - qemu reboot problem with seabios 1.16.0 [rhel.8.7]
  • BZ - 2084566 - Disable 5-level page tables when using -cpu max
  • BZ - 2089433 - [RFE] RFE backport allow enabling ZEROCOPY live migration to libvirt on RHEL8
  • BZ - 2089623 - Virt-v2v can't convert rhel8.6 guest from VMware on rhel8.6
  • BZ - 2091597 - updates fail when libguestfs-benchmarking is installed
  • BZ - 2092756 - [RFE] RFE backport allow enabling ZEROCOPY live migration to libvirt-python on RHEL8 to be consumed by VDSM
  • BZ - 2095758 - Regression in 'startupPolicy' behaviour for disks backed by a block device
  • BZ - 2097209 - [virtiofs] mount virtiofs failed: SELinux: (dev virtiofs, type virtiofs) getxattr errno 111
  • BZ - 2097652 - The migration port is not released if use it again for recovering postcopy migration
  • BZ - 2097947 - Not able to install windows 11 OS with vTPM in spec (RHEL 8.7)
  • BZ - 2100508 - Test for available issuercert before creating CA
  • BZ - 2100862 - CVE-2022-2211 libguestfs: Buffer overflow in get_keys leads to DoS
  • BZ - 2101575 - libvirt: SELinux labels are not set on UNIX sockets
  • BZ - 2101787 - [rhel.8.7] Loading a kernel/initrd is sometimes very slow
  • BZ - 2107954 - Unclear error message output when poweroff vm during postcopy migration.
  • BZ - 2110203 - zerocopy capability can be enabled when set migrate capabilities with multifd and compress/xbzrle together
  • BZ - 2111433 - Failed to restore vm after creating a snapshot for a booting vm with vtpm device
  • BZ - 2112296 - virtio-blk: Can't boot fresh installation from used 512 cluster_size image under certain conditions
  • BZ - 2120279 - Wrong max_sectors_kb and Maximum transfer length on the pass-through device [rhel-8.7]
  • BZ - 2127109 - Some packages in rhel 8.7 virt:rhel module are older than the ones in rhel 8.6.z