Oval Definition:oval:org.mitre.oval:def:27143
Revision Date:2014-12-01Version:4
Title:SUSE-SU-2014:1278-1 -- Security update for kvm
Description:kvm has been updated to fix issues in the embedded qemu: * CVE-2014-0223: An integer overflow flaw was found in the QEMU blockdriver for QCOW version 1 disk images. A user able to alter the QEMU diskimage files loaded by a guest could have used this flaw to corrupt QEMUprocess memory on the host, which could potentially have resulted inarbitrary code execution on the host with the privileges of the QEMU process. * CVE-2014-3461: A user able to alter the savevm data (either on thedisk or over the wire during migration) could have used this flaw to tocorrupt QEMU process memory on the (destination) host, which could havepotentially resulted in arbitrary code execution on the host with theprivileges of the QEMU process. * CVE-2014-0222: An integer overflow flaw was found in the QEMU blockdriver for QCOW version 1 disk images. A user able to alter the QEMU diskimage files loaded by a guest could have used this flaw to corrupt QEMUprocess memory on the host, which could have potentially resulted inarbitrary code execution on the host with the privileges of the QEMU process.Non-security bugs fixed: * Fix exceeding IRQ routes that could have caused freezes of guests. (bnc#876842) * Fix CPUID emulation bugs that may have broken Windows guests with newer -cpu types (bnc#886535)Security Issues: * CVE-2014-0222 * CVE-2014-0223 * CVE-2014-3461
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-0222
CVE-2014-0223
CVE-2014-3461
SUSE-SU-2014:1278-1
Platform(s):SUSE Linux Enterprise Desktop 11
SUSE Linux Enterprise Server 11
Product(s):kvm
Definition Synopsis
  • Operation system section
  • SUSE Linux Enterprise Server 11.x is installed
  • OR SUSE Linux Enterprise Desktop 11.x is installed
  • AND kvm RPM is earlier than 0:1.4.2-0.17.1
  • BACK