- Issued:
- 2018-04-10
- Updated:
- 2018-04-10
RHBA-2018:1105 - Bug Fix Advisory
Synopsis
qemu-kvm-rhev bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated qemu-kvm-rhev packages that fix several bugs and one one enhancement are now available for Red Hat Virtualization Host 7.
Description
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products.
This update fixes the following bugs:
- Previously, system calls to the address_space_to_flatview function in some cases targeted functions that were not sufficiently synchronized by the read-copy-update (RCU) mechanism. This was a potential security risk. The affected system calls have been fixed, and they can no longer be used as a vector for malicious code. (BZ#1554929)
- Under certain circumstances, snapshots of guests created in Red Hat Virtualization (RHV) could not be deleted due to an error in the snapshot locking mechanism. This update fixes RHV snapshot locking, and the affected snapshots can now be removed as expected. (BZ#1554946)
- Due to an error in the code for resizing the hashed page table (HPT), migrated guests on an IBM POWER host terminated unexpectedly. This update ensures that the size of the HPT is recorded correctly during migration, which prevents the described crashes from occurring. (BZ#1554956)
In addition, this update adds the following enhancement:
- Additional machine types have been introduced for qemu-kvm that improve the IBM POWER guest protection against the Spectre and Meltdown vulnerabilities. (BZ#1554951)
Users of qemu-kvm-rhev are advised to upgrade to these updated packages, which fix these bugs and add this enhancement. After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Virtualization 4 for RHEL 7 x86_64
- Red Hat Virtualization for IBM Power LE 4 for RHEL 7 ppc64le
Fixes
- BZ - 1554929 - incorrect locking (possible use-after-free) with bug 1481593 fix [rhel-7.5.z]
- BZ - 1554946 - [Regression] Cannot delete VM's snapshot [rhel-7.5.z]
- BZ - 1554956 - [ppc64] Migration will fail after HPT resizing [rhel-7.5.z]
CVEs
(none)
References
(none)
Red Hat Virtualization 4 for RHEL 7
| SRPM | |
|---|---|
| qemu-kvm-rhev-2.10.0-21.el7_5.1.src.rpm | SHA-256: e6f3a9a77ce4d9d9738bb35115e75f6e1ca39c95067f009e70691a3294135e17 |
| x86_64 | |
| qemu-img-rhev-2.10.0-21.el7_5.1.x86_64.rpm | SHA-256: 0c4904ca252882a053bd6d5130b9209e9c5265ee371ff7e28fd5ce9d080c8bfd |
| qemu-kvm-common-rhev-2.10.0-21.el7_5.1.x86_64.rpm | SHA-256: 6a41fd92753bbb74b5e82a1bf6871713a14176faf4d58e20ba1551e604e146f4 |
| qemu-kvm-rhev-2.10.0-21.el7_5.1.x86_64.rpm | SHA-256: 2032a85358ba61d7881ccecbb1b1851783d7557e82f101738dd89656e4b77b80 |
| qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.1.x86_64.rpm | SHA-256: ec7facd35ea0ce17dfa8ac8455e8916cb68ce52765502f7bb645092799a278e5 |
| qemu-kvm-tools-rhev-2.10.0-21.el7_5.1.x86_64.rpm | SHA-256: 35f8bc4bbc8e97a5ca60571bc4401df40be15431f930405ee56c9a6fafac9a71 |
Red Hat Virtualization for IBM Power LE 4 for RHEL 7
| SRPM | |
|---|---|
| qemu-kvm-rhev-2.10.0-21.el7_5.1.src.rpm | SHA-256: e6f3a9a77ce4d9d9738bb35115e75f6e1ca39c95067f009e70691a3294135e17 |
| ppc64le | |
| qemu-img-rhev-2.10.0-21.el7_5.1.ppc64le.rpm | SHA-256: 30ba9972b6e6fc42870bf0abe64384b154a905386006deecb2679c64d48bd953 |
| qemu-kvm-common-rhev-2.10.0-21.el7_5.1.ppc64le.rpm | SHA-256: 4c86ec19fd7d3f1ddfbd6dd79dcaf0206446c3bd5ae1446eec3c235143cd1fe6 |
| qemu-kvm-rhev-2.10.0-21.el7_5.1.ppc64le.rpm | SHA-256: 495ae7c1bed4dc4abcfc71ff8a3b2b6e11650926551207322166adc179bdce6e |
| qemu-kvm-rhev-debuginfo-2.10.0-21.el7_5.1.ppc64le.rpm | SHA-256: 313b922d1d8fd0959545d7e54cf0cee0f4ece1181281fb84dfb1c4602355e8ae |
| qemu-kvm-tools-rhev-2.10.0-21.el7_5.1.ppc64le.rpm | SHA-256: 3d05abf12c2ca95c131eeb4152f224fd3089f0892a81a45b7ce2243dfa55162b |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.