CESA-2020:4079 -- centos 7 qemu-kvmID: oval:org.secpod.oval:def:205678 | Date: (C)2020-11-10 (M)2023-12-20 |
Class: PATCH | Family: unix |
Kernel-based Virtual Machine is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix: * QEMU: usb: out-of-bounds r/w access issue while processing usb packets * QEMU: slirp: use-after-free in ip_reass function in ip_input.c For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.