Oracle Linux Security Advisory ELSA-2016-0997

https://linux.oracle.com/errata/ELSA-2016-0997.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
qemu-guest-agent-0.12.1.2-2.491.el6_8.1.i686.rpm

x86_64:
qemu-guest-agent-0.12.1.2-2.491.el6_8.1.x86_64.rpm
qemu-img-0.12.1.2-2.491.el6_8.1.x86_64.rpm
qemu-kvm-0.12.1.2-2.491.el6_8.1.x86_64.rpm
qemu-kvm-tools-0.12.1.2-2.491.el6_8.1.x86_64.rpm


SRPMS:
https://oss.oracle.com:443/ol6/SRPMS-updates/qemu-kvm-0.12.1.2-2.491.el6_8.1.src.rpm



Description of changes:

[0.12.1.2-2.491.el6_8.1]
- kvm-Add-vga.h-unmodified-from-Linux.patch [bz#1331407]
- kvm-vga.h-remove-unused-stuff-and-reformat.patch [bz#1331407]
- kvm-vga-use-constants-from-vga.h.patch [bz#1331407]
- kvm-vga-Remove-some-should-be-done-in-BIOS-comments.patch [bz#1331407]
- kvm-vga-fix-banked-access-bounds-checking-CVE-2016-3710.patch [bz#1331407]
- kvm-vga-add-vbe_enabled-helper.patch [bz#1331407]
- kvm-vga-factor-out-vga-register-setup.patch [bz#1331407]
- kvm-vga-update-vga-register-setup-on-vbe-changes.patch [bz#1331407]
- kvm-vga-make-sure-vga-register-setup-for-vbe-stays-intac.patch 
[bz#1331407]
- Resolves: bz#1331407
   (EMBARGOED CVE-2016-3710 qemu-kvm: qemu: incorrect banked access 
bounds checking in vga module [rhel-6.8.z])

[0.12.1.2-2.491.el6]
- Revert "warning when  CPU threads>1 for non-Intel CPUs" fix

[0.12.1.2-2.490.el6]
- kvm-qemu-ga-implement-win32-guest-set-user-password.patch [bz#1174181]
- kvm-util-add-base64-decoding-function.patch [bz#1174181]
- kvm-qga-convert-to-use-error-checked-base64-decode.patch [bz#1174181]
- kvm-qga-use-more-idiomatic-qemu-style-eol-operators.patch [bz#1174181]
- kvm-qga-use-size_t-for-wcslen-return-value.patch [bz#1174181]
- kvm-qga-use-wide-chars-constants-for-wchar_t-comparisons.patch 
[bz#1174181]
- kvm-qga-fix-off-by-one-length-check.patch [bz#1174181]
- kvm-qga-check-utf8-to-utf16-conversion.patch [bz#1174181]
- Resolves: bz#1174181
   (RFE: provide QEMU guest agent command for setting root account 
password (Linux guest))

[0.12.1.2-2.489.el6]
- kvm-hw-qxl-qxl_send_events-nop-if-stopped.patch [bz#1290743]
- kvm-block-mirror-fix-full-sync-mode-when-target-does-not.patch [bz#971312]
- Resolves: bz#1290743
   (qemu-kvm core dumped when repeat system_reset 20 times during guest 
boot)
- Resolves: bz#971312
   (block: Mirroring to raw block device doesn't zero out unused blocks)

* Mon Feb 08 2016 Miroslav Rezanina 

Oracle6: ELSA-2016-0997: qemu Important Security Update

The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network:

Summary

[0.12.1.2-2.491.el6_8.1] - kvm-Add-vga.h-unmodified-from-Linux.patch [bz#1331407] - kvm-vga.h-remove-unused-stuff-and-reformat.patch [bz#1331407] - kvm-vga-use-constants-from-vga.h.patch [bz#1331407] - kvm-vga-Remove-some-should-be-done-in-BIOS-comments.patch [bz#1331407] - kvm-vga-fix-banked-access-bounds-checking-CVE-2016-3710.patch [bz#1331407] - kvm-vga-add-vbe_enabled-helper.patch [bz#1331407] - kvm-vga-factor-out-vga-register-setup.patch [bz#1331407] - kvm-vga-update-vga-register-setup-on-vbe-changes.patch [bz#1331407] - kvm-vga-make-sure-vga-register-setup-for-vbe-stays-intac.patch [bz#1331407] - Resolves: bz#1331407 (EMBARGOED CVE-2016-3710 qemu-kvm: qemu: incorrect banked access bounds checking in vga module [rhel-6.8.z]) [0.12.1.2-2.491.el6] - Revert "warning when CPU threads>1 for non-Intel CPUs" fix [0.12.1.2-2.490.el6] - kvm-qemu-ga-implement-win32-guest-set-user-password.patch [bz#1174181] - kvm-util-add-base64-decoding-function.patch [bz#1174181] - kvm-qga...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol6/SRPMS-updates/qemu-kvm-0.12.1.2-2.491.el6_8.1.src.rpm

x86_64

qemu-guest-agent-0.12.1.2-2.491.el6_8.1.x86_64.rpm qemu-img-0.12.1.2-2.491.el6_8.1.x86_64.rpm qemu-kvm-0.12.1.2-2.491.el6_8.1.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.491.el6_8.1.x86_64.rpm

aarch64

i386

qemu-guest-agent-0.12.1.2-2.491.el6_8.1.i686.rpm

Severity

Related News