{"schema_version": "1.3.1", "id": "RLSA-2021:4191", "modified": "2023-02-02T13:29:41.677191Z", "published": "2021-11-09T08:35:34Z", "related": ["CVE-2020-15859", "CVE-2021-3592", "CVE-2021-3593", "CVE-2021-3594", "CVE-2021-3595", "CVE-2021-3631", "CVE-2021-3667"], "summary": "Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update", "details": "Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.\n\nSecurity Fix(es):\n\n* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)\n\n* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)\n\n* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)\n\n* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)\n\n* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)\n\n* libvirt: Insecure sVirt label generation (CVE-2021-3631)\n\n* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "hivex", "purl": "pkg:rpm/rocky-linux/hivex?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.3.18-21.module+el8.4.0+642+7e26f5e1"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "hivex", "purl": "pkg:rpm/rocky-linux/hivex?distro=rocky-linux-8-5-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.3.18-21.module+el8.5.0+670+c4aa478c"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libguestfs", "purl": "pkg:rpm/rocky-linux/libguestfs?distro=rocky-linux-8-5-legacy&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.40.2-28.module+el8.5.0+670+c4aa478c"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libguestfs-winsupport", "purl": "pkg:rpm/rocky-linux/libguestfs-winsupport?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:8.2-1.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libiscsi", "purl": "pkg:rpm/rocky-linux/libiscsi?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.18.0-8.module+el8.7.0+1084+97b81f61"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libiscsi", "purl": "pkg:rpm/rocky-linux/libiscsi?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.18.0-8.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libiscsi", "purl": "pkg:rpm/rocky-linux/libiscsi?distro=rocky-linux-8-6-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.18.0-8.module+el8.6.0+847+b490afdd"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libnbd", "purl": "pkg:rpm/rocky-linux/libnbd?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.2-1.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libvirt", "purl": "pkg:rpm/rocky-linux/libvirt?distro=rocky-linux-8-5-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:6.0.0-37.module+el8.5.0+670+c4aa478c"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libvirt-dbus", "purl": "pkg:rpm/rocky-linux/libvirt-dbus?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.3.0-2.module+el8.7.0+1084+97b81f61"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libvirt-dbus", "purl": "pkg:rpm/rocky-linux/libvirt-dbus?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.3.0-2.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libvirt-dbus", "purl": "pkg:rpm/rocky-linux/libvirt-dbus?distro=rocky-linux-8-6-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.3.0-2.module+el8.6.0+847+b490afdd"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libvirt-python", "purl": "pkg:rpm/rocky-linux/libvirt-python?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:6.0.0-1.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "nbdkit", "purl": "pkg:rpm/rocky-linux/nbdkit?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.16.2-4.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "netcf", "purl": "pkg:rpm/rocky-linux/netcf?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.8-12.module+el8.7.0+1084+97b81f61"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "netcf", "purl": "pkg:rpm/rocky-linux/netcf?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.8-12.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "netcf", "purl": "pkg:rpm/rocky-linux/netcf?distro=rocky-linux-8-6-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.8-12.module+el8.6.0+847+b490afdd"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "perl-Sys-Virt", "purl": "pkg:rpm/rocky-linux/perl-Sys-Virt?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:6.0.0-1.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "qemu-kvm", "purl": "pkg:rpm/rocky-linux/qemu-kvm?distro=rocky-linux-8-5-legacy&epoch=5"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "5:4.2.0-59.module+el8.5.0+670+c4aa478c"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "seabios", "purl": "pkg:rpm/rocky-linux/seabios?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.13.0-2.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "sgabios", "purl": "pkg:rpm/rocky-linux/sgabios?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:0.20170427git-3.module+el8.7.0+1084+97b81f61"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "sgabios", "purl": "pkg:rpm/rocky-linux/sgabios?distro=rocky-linux-8-4-legacy&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:0.20170427git-3.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "sgabios", "purl": "pkg:rpm/rocky-linux/sgabios?distro=rocky-linux-8-6-legacy&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:0.20170427git-3.module+el8.6.0+847+b490afdd"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "supermin", "purl": "pkg:rpm/rocky-linux/supermin?distro=rocky-linux-8-4-legacy&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:5.1.19-10.module+el8.4.0+534+4680a14e"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2021:4191"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1855250"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1859168"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1929357"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1932823"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1933640"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1934509"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1939418"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1942805"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1961562"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1967329"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1967496"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1967716"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1967914"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1969848"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970484"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970487"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970489"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970491"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1977726"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1982134"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1986094"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1994041"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}