Security Vulnerabilities fixed in qemu-kvm-ma RHSA-2021:0346

description-logoDescription

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-ma packages provide the user-space component for running virtual machines that use KVM on the IBM z Systems, IBM Power, and 64-bit ARM architectures. Security Fix(es): QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983) QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c (CVE-2020-16092) QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983) QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c (CVE-2020-16092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

affected-products-logoAffected Applications

qemu-kvm-ma

CVE References

CVE-2020-1983 CVE-2020-16092