As you may have already heard, an industry-wide issue was found in the way
many modern microprocessor designs have implemented speculative execution
of Load & Store instructions.
This issue is well described by CVE-2018-3639 announce available at
oVirt team has released right now an update of ovirt-engine to version
184.108.40.206 which add support for SSBD CPUs in order to mitigate the security
If you are running oVirt on Red Hat Enterprise Linux, please apply updates
described in https://access.redhat.com/security/cve/cve-2018-3639
If you are running oVirt on CentOS Linux please apply updated described by:
CESA-2018:1629 Important CentOS 7 kernel Security Update
CESA-2018:1632 Important CentOS 7 libvirt Security Update
CESA-2018:1649 Important CentOS 7 java-1.8.0-openjdk Security Update
CESA-2018:1648 Important CentOS 7 java-1.7.0-openjdk Security Update
An update for qemu-kvm-ev has been also tagged for release and announced
CESA-2018:1655 Important: qemu-kvm-ev security update
but due to some issues in CentOS release process for Virt SIG content, it
is not yet available on mirrors.
We are working with CentOS community to get the packages signed and
published as soon as possible.
In the meanwhile you can still get the update package by enabling the test
your systems or manually installing the package from the repository.
If you're running oVirt on a different Linux distribution, please check
with your vendor for available updates.
Please note that to fully mitigate this vulnerability, system
administrators must apply both hardware “microcode” updates and software
patches that enable new functionality.
At this time, microprocessor microcode will be delivered by the individual
The oVirt team recommends end users and systems administrator to apply any
available updates as soon as practical.
ASSOCIATE MANAGER, SOFTWARE ENGINEERING, EMEA ENG VIRTUALIZATION R&D
Red Hat EMEA <https://www.redhat.com/>