Fedora alert FEDORA-2008-1973 (kvm)
From: | updates@fedoraproject.org | |
To: | fedora-package-announce@redhat.com | |
Subject: | [SECURITY] Fedora 7 Update: kvm-36-8.fc7 | |
Date: | Mon, 25 Feb 2008 17:26:06 -0700 | |
Message-ID: | <200802260026.m1Q0PnZY026144@bastion.fedora.phx.redhat.com> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-1973 2008-02-25 22:15:01 -------------------------------------------------------------------------------- Name : kvm Product : Fedora 7 Version : 36 Release : 8.fc7 URL : http://kvm.sf.net Summary : Kernel-based Virtual Machine Description : KVM (for Kernel-based Virtual Machine) is a full virtualization solution for Linux on x86 hardware. Using KVM, one can run multiple virtual machines running unmodified Linux or Windows images. Each virtual machine has private virtualized hardware: a network card, disk, graphics adapter, etc. -------------------------------------------------------------------------------- Update Information: Ian Jackson discovered that accesses beyond end of qemu emulated disk devices can result in accesses to emulator's virtual memory space accesses and thus can allow user with sufficient privilege in guest (root, as this would need modification to kernel's driver) to break out of VM. http://marc.info/?l =debian-security&m=120343592917055&w=2 -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 23 2008 Daniel P. Berrange <berrange@redhat.com> - 36-8.fc7 - Fix block device extents check (rhbz #433560) * Mon Oct 15 2007 Daniel P. Berrange <berrange@redhat.com> - 36-7 - Fixed PXE boot when KVM is enabled (rhbz #331191) * Wed Sep 26 2007 Daniel P. Berrange <berrange@redhat.com> - 36-6 - Fixed rtl8139 checksum calculation for Vista (rhbz #308201) * Mon Sep 24 2007 Jeremy Katz <katzj@redhat.com> - 36-5 - fix build on x86_64 * Mon Sep 24 2007 Jeremy Katz <katzj@redhat.com> - 36-3 - add support for selecting boot device at runtime * Tue Sep 4 2007 Jeremy Katz <katzj@redhat.com> - 36-2 - rebase vnc auth patch * Tue Sep 4 2007 Jeremy Katz <katzj@redhat.com> - 36-1 - update to kvm-36 * Mon Aug 27 2007 Daniel P. Berrange <berrange@redhat.com> - 35-3 - Added patch for VNC password auth and TLS+x509 cert auth * Mon Aug 20 2007 Jeremy Katz <katzj@redhat.com> - 35-2 - add fix for ATAPI from upstream qemu * Mon Aug 20 2007 Jeremy Katz <katzj@redhat.com> - 35-1 - update to kvm-35 - patch to use -Wl,--build-id so that we get debuginfo * Thu Jul 19 2007 Jeremy Katz <katzj@redhat.com> - 31-1 - update to kvm-31 * Mon Jul 16 2007 Jeremy Katz <katzj@redhat.com> - 28-2 - add patch from danpb to fix mac addrs of multiple 8139 nics (#247641) * Wed Jun 13 2007 Jeremy Katz <katzj@redhat.com> - 28-1 - update to kvm-28 * Sat Jun 9 2007 Jeremy Katz <katzj@redhat.com> - 27-1 - update to kvm-27 * Tue May 29 2007 Jeremy Katz <katzj@redhat.com> - 26-1 - update to kvm-26 -------------------------------------------------------------------------------- References: [ 1 ] Bug #433560 - Qemu insufficient block device address range checking https://bugzilla.redhat.com/show_bug.cgi?id=433560 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update kvm' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...