Operating System:

[RedHat]

Published:

16 August 2018

Protect yourself against future threats.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2018.2368
                Important: rhev-hypervisor7 security update
                              16 August 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           rhev-hypervisor7
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 6
                   Red Hat Enterprise Linux Server 7
Impact/Access:     Access Privileged Data -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-3646 CVE-2018-3620 

Reference:         ESB-2018.2355
                   ESB-2018.2352
                   ESB-2018.2348.2
                   ESB-2018.2344
                   ESB-2018.2343

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2018:2404

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: rhev-hypervisor7 security update
Advisory ID:       RHSA-2018:2404-01
Product:           Red Hat Virtualization
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:2404
Issue date:        2018-08-15
CVE Names:         CVE-2018-3620 CVE-2018-3646 
=====================================================================

1. Summary:

An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and
Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents
Extended Lifecycle Support for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

RHEL 7-based RHEV-H ELS - noarch
RHEV Hypervisor for RHEL-6 ELS - noarch

3. Description:

The rhev-hypervisor7 package provides a Red Hat Enterprise Virtualization
Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor
is a dedicated Kernel-based Virtual Machine (KVM) hypervisor. It includes
everything necessary to run and manage virtual machines: A subset of the
Red Hat Enterprise Linux operating environment and the Red Hat Enterprise
Virtualization Agent.

Security Fix(es):

* Modern operating systems implement virtualization of physical memory to
efficiently use available system resources and provide inter-domain
protection through access control and isolation. The L1TF issue was found
in the way the x86 microprocessor designs have implemented speculative
execution of instructions (a commonly used performance optimisation) in
combination with handling of page-faults caused by terminated virtual to
physical address resolving process. As a result, an unprivileged attacker
could use this flaw to read privileged memory of the kernel or other
processes and/or cross guest/host boundaries to read host memory by
conducting targeted cache side-channel attacks. (CVE-2018-3620,
CVE-2018-3646)

Red Hat would like to thank Intel OSSIRT (Intel.com) for reporting these
issues.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/2974891

5. Bugs fixed (https://bugzilla.redhat.com/):

1585005 - CVE-2018-3646 CVE-2018-3620 Kernel: hw: cpu: L1 terminal fault (L1TF)
1614065 - [Tracker] Tracking bug for RHEV-H 3.6.13 respin

6. Package List:

RHEV Hypervisor for RHEL-6 ELS:

Source:
rhev-hypervisor7-7.3-20180813.0.el6ev.src.rpm

noarch:
rhev-hypervisor7-7.3-20180813.0.el6ev.noarch.rpm

RHEL 7-based RHEV-H ELS:

Source:
rhev-hypervisor7-7.3-20180813.0.el7ev.src.rpm

noarch:
rhev-hypervisor7-7.3-20180813.0.el7ev.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-3620
https://access.redhat.com/security/cve/CVE-2018-3646
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/security/vulnerabilities/L1TF

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW3RGDtzjgjWX9erEAQhb4A//ZwpUUnLxZZXrBCi9u0NAJQrIIS6gQmn2
Jmgd7S/tSAlS3d0sslY5yx9eJjWp3t7LWbKwQXpP9+brvClMCP0abCj49vyGxE3o
rMiAk/Cyy7kBTTSMMRQFePa9tl5lJW6l7Qk5z2qcspxTAk/ysiC14heG8AcdXAv1
xVdsRiuXhfF00oIRPvMsTFi3P/03PiZnOHPo6cXw9FaIBu9sspu++07RQRj8Id6B
7C0v6yE6lpEvyDy2jgrzoPYDpMnRRwt/zxXSnMKGBjRhRSU+svVzRqM3fR2wTQBa
1QEFC9G0HZ1nEKcGnDRzKKwpU0OfilxdT4aUAzDxY5TsNV80qJIRQO8kQgSpJcPW
+SFH2Nks9fu6Mdaa2dwxJBE/QRasKbSQXoo58v40TVou9lBXA1tQRmV7rtg4/TpW
GyNQ0UXf0p6ViBD54BoSnwelh5XcPJJGRPv9UB5K44I6++N0CQnpeqcXIVXZMoLU
WlgBOjgAAH2Thb8W1B2447JdNgE7e6hY6JDcRQ13mILc643M/zWURcn2/4cyB+xH
NL7TbbYLN6ZGZDTK8AF3TqItLFc/lQIbg0IGeo7IvXkNkjEwk5if2owz5JBNLU6f
0uzhsJS4MbF55p/b2O5TYTHFBhAfBOizjVANEjrzkDC77x1aE9iC+Ce781vo/nUw
Cxlql9oitcg=
=tuP7
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBW3T9J2aOgq3Tt24GAQiAIQ//cvdT7fwa8ZB6T3x7xGvMJVx2+USKqkAw
oG+2agS3lv5Cu+axID4VIPFm2U7lpb2CkF4eRT4vBRSOyX2Z806jQsORp+ZoNE4V
7Puy2Gj6WZZCM+DOI6oMD/xQoeIHVuUaFNd5fkeEWfv64E2iB8dGXujTl4AdDR6B
QDLCLYWUA9NRA9sIUCeXLMJwUD5/MSZg/pp9ulhJjC7ZHGW3rzs1S6IG2m+PWF76
Q6iMhF8Hf1bbgl190QjWlCIUps/YiucVUqY5H2Euy04a3sRnMeXdciFb8oT6gl1Z
OLCIR4ZTiAdlN7S3pXxdYXxVZoTxdq5hrU3N5xcN/vtoyFWHvH9BVh03ysYIdhdD
00V1yQqZ1wDFjHZY6jBiu4tASYZCpJiDP4jzuRiNrNeqKZx4YyzZLUb/f10VPXR1
kDaLZxcllKoj1FVcpJmEJ/kbbkBSt3KSGe4Ghg6mIQGOCpz5Ltl/NPcm1WcdyMLD
7akA5Kjyd2bG6vguF1/KSCxdeWmdqLqqiuBgf2IwE4yAB/dFUbfaknUVWBYSfTHq
l+u8FyUs9ckZY0YOifxEDRY1dwhnokKZknL0ipo5Tareg+n1rOkeffTiAoFls/Wn
eS1xJ8PUE7Y8KehiTFGRSBrrrGG8zWZoX5/1NQIuhlA5cPq8uEBIOfC4/G6IDI4N
/aE98puvrVI=
=eR6Y
-----END PGP SIGNATURE-----