hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space. Reference: https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01959.html
Mitigation: Use `-device bochs-display` as conventional PCI device only.
Statement: This flaw does not affect the module stream`virt:8.1/qemu-kvm` as shipped with RHEL Advanced Virtualization, as it already includes the patch. Several other packages are unaffected because they do not include PCIe support: * `kvm` and `xen` as shipped with Red Hat Enterprise Linux 5 * `qemu-kvm` as shipped with Red Hat Enterprise Linux 6 and 7 * `qemu-kvm-rhev` as shipped with Red Hat Enterprise Linux 7 * `virt:rhel/qemu-kvm` as shipped with Red Hat Enterprise Linux 8 * `qemu-kvm-rhev` as shipped with Red Hat OpenStack Platform 10 and 13
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-15034