[FEDORA-2018-44f8a7454d] Fedora 28: qemu

Severity Medium
Affected Packages 1
CVEs 1

New CPU features for speculative store bypass (CVE-2018-3639) On Intel x86
hosts, the "ssbd" feature must be explicitly added to any virtual machines that
are not using host-passthrough/host-model CPU setup. NB this requires new
microcode too, which is not yet available in Fedora microcode_ctl RPMs. On AMD
x86 hosts, the "virt-ssbd" feature must be explicitly added to any virtual
machines that are not using host-passthrough/host-model CPU setup. There is no
microcode dependency for AMD as this is a virtualized CPUID feature. In both
cases, kernel >= 4.16.10-301 is required on the host and guest in order to
activate the fix.

Package Affected Version
pkg:rpm/fedora/qemu?distro=fedora-28 < 2.11.1.3.fc28
ID
FEDORA-2018-44f8a7454d
Severity
medium
Severity from
CVE-2018-3639
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2018-44f8a7454d
Published
2018-06-21T15:02:25
(6 years ago)
Modified
2018-06-21T15:02:25
(6 years ago)
Rights
Copyright 2018 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1566890 Bug #1566890 - CVE-2018-3639 hw: cpu: speculative store bypass https://bugzilla.redhat.com/show_bug.cgi?id=1566890
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/qemu?distro=fedora-28 fedora qemu < 2.11.1.3.fc28 fedora-28
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...