An update for qemu-kvm-rhev is now available for Red Hat Enterprise LinuxOpenStack Platform 6.0 (Juno) for RHEL 7.Red Hat Product Security has rated this update as having a security impact ofModerate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linuxon AMD64 and Intel 64 systems. The qemu-kvm-rhev package provides the user-spacecomponent for running virtual machines using KVM in environments managed by RedHat Enterprise Virtualization Manager.Security Fix(es):* Quick Emulator(Qemu) built with the Block driver for iSCSI images support(virtio-blk) is vulnerable to a heap buffer overflow issue. It could occur whileprocessing iSCSI asynchronous I/O ioctl(2) calls. A user inside guest could usethis flaw to crash the Qemu process resulting in DoS or potentially leverage itto execute arbitrary code with privileges of the Qemu process on the host.(CVE-2016-5126)* Quick emulator(Qemu) built with the virtio framework is vulnerable to anunbounded memory allocation issue. It was found that a malicious guest usercould submit more requests than the virtqueue size permits. Processing a requestallocates a VirtQueueElement and therefore causes unbounded memory allocation onthe host controlled by the guest. (CVE-2016-5403)Red Hat would like to thank hongzhenhao (Marvel Team) for reportingCVE-2016-5403.
For details on how to apply this update, which includes the changes described inthis advisory, refer to: installing this update, shut down all running virtual machines. Once allvirtual machines have shut down, start them again for this update to takeeffect.Red Hat OpenStack 6.0 for RHEL 7

