qemu vulnerabilities (CVE-2014-0150, CVE-2014-2894)

Bug #1324927 reported by Michael Semenov
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Fix Released
Critical
MOS Linux
4.1.x
Won't Fix
Critical
MOS Linux
5.0.x
Won't Fix
High
MOS Linux

Bug Description

Need to apply a patch for CVE-2014-0150, CVE-2014-2894, provided by Ubuntu.

Vulnerabilities links:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0150
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2894

Patches can be found here(for different versions):
https://launchpad.net/ubuntu/+source/qemu-kvm
https://launchpad.net/ubuntu/+source/qemu

Tags: mos-linux qemu

CVE References

affects: fuel → qemu-kvm (Ubuntu)
Changed in qemu-kvm (Ubuntu):
assignee: nobody → Fuel Linux Hardening Team (fuel-linux)
status: New → In Progress
affects: qemu-kvm (Ubuntu) → fuel
information type: Private Security → Public Security
Changed in fuel:
status: In Progress → Fix Committed
Mike Scherbakov (mihgen)
Changed in fuel:
milestone: none → 5.1
Revision history for this message
OSCI Robot (oscirobot) wrote :

Package qemu has been built from changeset: http://gerrit.mirantis.com/16090
DEB Repository URL: http://osci-obs.vm.mirantis.net:82/ubuntu-fuel-5.0-stable-16090/ubuntu
You can build an ISO with this package:
make iso EXTRA_DEB_REPOS="http://osci-obs.vm.mirantis.net:82/ubuntu-fuel-5.0-stable-16090/ubuntu /"

Changed in fuel:
status: Fix Committed → In Progress
Revision history for this message
OSCI Robot (oscirobot) wrote :

Package qemu has been built from changeset: http://gerrit.mirantis.com/16293
RPM Repository URL: http://osci-obs.vm.mirantis.net:82/centos-fuel-5.0-stable-16293/centos
You can build an ISO with this package:
make iso EXTRA_RPM_REPOS="osci-testing,http://osci-obs.vm.mirantis.net:82/centos-fuel-5.0-stable-16293/centos"

Changed in fuel:
assignee: Fuel Linux Hardening Team (fuel-linux) → MOS Linux (mos-linux)
Changed in fuel:
importance: Undecided → Critical
Revision history for this message
Dmitry Borodaenko (angdraug) wrote :

Patches above are targeted at 5.0, we're going to need the same updated packages for 4.1 and 5.1 as well.

tags: added: mos-linux
Revision history for this message
Michael Semenov (msemenov) wrote :

Fixed by upgrading qemu to 2.0
https://bugs.launchpad.net/fuel/+bug/1321701

Revision history for this message
Michael Semenov (msemenov) wrote :

Fixed only in 5.1.
4.1.x - Won't Fix
5.0.x - Won't Fix

Changed in fuel:
status: In Progress → Opinion
Changed in fuel:
status: Opinion → Fix Committed
tags: added: rca-done
tags: removed: rca-done
Changed in fuel:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.