Oracle Linux 6167 Published by

A qemu security update has been released for Oracle Linux 7.



El-errata: ELSA-2021-9335 Important: Oracle Linux 7 qemu security update


Oracle Linux Security Advisory ELSA-2021-9335

  http://linux.oracle.com/errata/ELSA-2021-9335.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

i386:

x86_64:
qemu-common-4.2.1-10.el7.x86_64.rpm
qemu-system-x86-core-4.2.1-10.el7.x86_64.rpm
qemu-block-gluster-4.2.1-10.el7.x86_64.rpm
qemu-block-iscsi-4.2.1-10.el7.x86_64.rpm
qemu-block-rbd-4.2.1-10.el7.x86_64.rpm
qemu-img-4.2.1-10.el7.x86_64.rpm
qemu-4.2.1-10.el7.x86_64.rpm
qemu-kvm-4.2.1-10.el7.x86_64.rpm
qemu-kvm-core-4.2.1-10.el7.x86_64.rpm
qemu-system-x86-4.2.1-10.el7.x86_64.rpm

SRPMS:
  http://oss.oracle.com/ol7/SRPMS-updates/qemu-4.2.1-10.el7.src.rpm

Related CVEs:

CVE-2020-27661
CVE-2021-20257



Description of changes:

[15:4.2.1-10.el7]
- e1000: fail early for evil descriptor (Jason Wang) [Orabug: 32560552] {CVE-2021-20257}
- Document CVE-2020-27661 as fixed (Mark Kanda) [Orabug: 32960200] {CVE-2020-27661}
- block: Avoid stale pointer dereference in blk_get_aio_context() (Greg Kurz)
- block: Fix blk->in_flight during blk_wait_while_drained() (Kevin Wolf)
- block: Increase BB.in_flight for coroutine and sync interfaces (Kevin Wolf)
- block-backend: Reorder flush/pdiscard function definitions (Kevin Wolf)