| Revision Date: | 2014-12-01 | Version: | 4 |
| Title: | SUSE-SU-2014:1278-1 -- Security update for kvm |
| Description: | kvm has been updated to fix issues in the embedded qemu: * CVE-2014-0223: An integer overflow flaw was found in the QEMU blockdriver for QCOW version 1 disk images. A user able to alter the QEMU diskimage files loaded by a guest could have used this flaw to corrupt QEMUprocess memory on the host, which could potentially have resulted inarbitrary code execution on the host with the privileges of the QEMU process. * CVE-2014-3461: A user able to alter the savevm data (either on thedisk or over the wire during migration) could have used this flaw to tocorrupt QEMU process memory on the (destination) host, which could havepotentially resulted in arbitrary code execution on the host with theprivileges of the QEMU process. * CVE-2014-0222: An integer overflow flaw was found in the QEMU blockdriver for QCOW version 1 disk images. A user able to alter the QEMU diskimage files loaded by a guest could have used this flaw to corrupt QEMUprocess memory on the host, which could have potentially resulted inarbitrary code execution on the host with the privileges of the QEMU process.Non-security bugs fixed: * Fix exceeding IRQ routes that could have caused freezes of guests. (bnc#876842) * Fix CPUID emulation bugs that may have broken Windows guests with newer -cpu types (bnc#886535)Security Issues: * CVE-2014-0222 * CVE-2014-0223 * CVE-2014-3461 |
| Family: | unix | Class: | patch |
| Status: | ACCEPTED | Reference(s): | CVE-2014-0222 CVE-2014-0223 CVE-2014-3461 SUSE-SU-2014:1278-1
|
| Platform(s): | SUSE Linux Enterprise Desktop 11 SUSE Linux Enterprise Server 11
| Product(s): | kvm
|
| Definition Synopsis |
| Operation system section SUSE Linux Enterprise Server 11.x is installed
OR SUSE Linux Enterprise Desktop 11.x is installed
AND kvm RPM is earlier than 0:1.4.2-0.17.1
|