diff --git a/docs/source/security/2015/20150519_openssl.rst b/docs/source/security/2015/20150519_openssl.rst index 35220c4d0..0affd1f4a 100644 --- a/docs/source/security/2015/20150519_openssl.rst +++ b/docs/source/security/2015/20150519_openssl.rst @@ -4,7 +4,7 @@ Advisory CVEs ------------- -* CVE-2015-3456 - **(aka VENOM) is a security flaw in the QEMU's Floppy Disk Controller (FDC) emulation.** +* CVE-2015-3456 - **(aka VENOM) is a security flaw in the QEMU's Floppy Disk Controller (FDC) emulation.** VENOM vulnerability could expose virtual machines on unpatched host systems @@ -22,6 +22,6 @@ The VENOM bug (CVE-2015-3456) exists in the virtual Floppy Disk Controller for t Action ------ -xCAT does not ship any rpms that have QEMU component directly. However xCAT does make system calls to QEMU when doing KVM/Xen visualization. If you are using xCAT to manage KVM or Xen hosts and quests, get the latest rpms that have QEMU component from the os distro and do a upgrade on both xCAT management node and the KVM/Xen hosts. +xCAT does not ship any rpms that have QEMU component directly. However xCAT does make system calls to QEMU when doing KVM/Xen visualization. If you are using xCAT to manage KVM or Xen hosts and quests, get the latest rpms that have QEMU component from the os distro and do a upgrade on both xCAT management node and the KVM/Xen hosts.