Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for qemu (Important) |
Description: |
This update for qemu to version 2.9.1 fixes several issues.
It also announces that the qed storage format will be no longer supported in SLE 15 (fate#324200).
These security issues were fixed:
- CVE-2017-15268: Qemu allowed remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c (bsc#1062942) - CVE-2017-15289: The mode4and5 write functions allowed local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation (bsc#1063122) - CVE-2017-15038: Race condition in the v9fs_xattrwalk function local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes (bsc#1062069) - CVE-2017-10911: The make_response function in the Linux kernel allowed guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures (bsc#1057378) - CVE-2017-12809: The IDE disk and CD/DVD-ROM Emulator support allowed local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive (bsc#1054724) - CVE-2017-14167: Integer overflow in the load_multiboot function allowed local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write (bsc#1057585) - CVE-2017-13672: The VGA display emulator support allowed local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update (bsc#1056334) - CVE-2017-13711: Use-after-free vulnerability allowed attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets (bsc#1056291).
These non-security issues were fixed:
- Fixed not being able to build from rpm sources due to undefined macro (bsc#1057966) - Fiedx package build failure against new glibc (bsc#1055587)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1002998 1027519 1031875 1031877 1031879 1031886 1032880 1054724 1055587 1056058 1056291 1056334 1057378 1057585 1057966 1058058 1062069 1062942 1063122 1064455 1066242 1072322 1087289 1090766 1094725 1095242 1096224 1097410 1097521 1097522 1097523 1104668 1112039 1114592 1135254 1137443 1141897 1142649 1142654 1148517 1149145 954204 CVE-2012-2944 CVE-2014-0011 CVE-2014-3467 CVE-2014-3468 CVE-2014-3469 CVE-2014-8240 CVE-2015-0255 CVE-2015-2698 CVE-2015-2806 CVE-2015-7514 CVE-2016-0705 CVE-2016-7945 CVE-2016-7946 CVE-2017-10911 CVE-2017-12809 CVE-2017-13672 CVE-2017-13711 CVE-2017-14167 CVE-2017-14919 CVE-2017-15038 CVE-2017-15268 CVE-2017-15289 CVE-2017-15896 CVE-2017-3732 CVE-2017-3735 CVE-2017-3736 CVE-2017-3738 CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395 CVE-2017-7396 CVE-2017-9798 CVE-2018-0495 CVE-2018-11806 CVE-2018-12539 CVE-2018-12891 CVE-2018-12892 CVE-2018-12893 CVE-2018-1517 CVE-2018-1656 CVE-2018-18386 CVE-2018-2940 CVE-2018-2952 CVE-2018-2964 CVE-2018-2973 CVE-2018-3665 CVE-2019-12735 CVE-2019-14250 CVE-2019-15847 SUSE-SU-2015:2302-1 SUSE-SU-2016:3047-1 SUSE-SU-2017:1093-1 SUSE-SU-2017:2718-1 SUSE-SU-2017:2924-1 SUSE-SU-2018:0293-1 SUSE-SU-2018:2081-1 SUSE-SU-2018:2089-1 SUSE-SU-2018:2839-1 SUSE-SU-2019:1456-1 SUSE-SU-2020:0394-1
|
Platform(s): | openSUSE Leap 15.0 openSUSE Leap 15.1 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.0 is installed AND Package Information
gdk-pixbuf-lang-2.36.11-lp150.3 is installed
OR gdk-pixbuf-query-loaders-2.36.11-lp150.3 is installed
OR gdk-pixbuf-thumbnailer-2.36.11-lp150.3 is installed
OR libgdk_pixbuf-2_0-0-2.36.11-lp150.3 is installed
OR typelib-1_0-GdkPixbuf-2_0-2.36.11-lp150.3 is installed
|
Definition Synopsis |
openSUSE Leap 15.1 is installed
AND Package Information
chromedriver-75.0.3770.80-lp151.2.6 is installed
OR chromium-75.0.3770.80-lp151.2.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
qemu-2.9.1-6.6 is installed
OR qemu-block-curl-2.9.1-6.6 is installed
OR qemu-ipxe-1.0.0-6.6 is installed
OR qemu-kvm-2.9.1-6.6 is installed
OR qemu-seabios-1.10.2-6.6 is installed
OR qemu-sgabios-8-6.6 is installed
OR qemu-tools-2.9.1-6.6 is installed
OR qemu-vgabios-1.10.2-6.6 is installed
OR qemu-x86-2.9.1-6.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
libtasn1-3.7-4 is installed
OR libtasn1-6-3.7-4 is installed
OR libtasn1-6-32bit-3.7-4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_74-60_64_82-default-9-2 is installed
OR kgraft-patch-3_12_74-60_64_82-xen-9-2 is installed
OR kgraft-patch-SLE12-SP1_Update_25-9-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND Package Information
libupsclient1-2.7.1-4 is installed
OR nut-2.7.1-4 is installed
OR nut-drivers-net-2.7.1-4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND Package Information
gvim-7.4.326-17.3 is installed
OR vim-7.4.326-17.3 is installed
OR vim-data-7.4.326-17.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND ucode-intel-20180425-13.20 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
MozillaFirefox-52.8.1esr-109.34 is installed
OR MozillaFirefox-devel-52.8.1esr-109.34 is installed
OR MozillaFirefox-translations-52.8.1esr-109.34 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
crash-7.1.8-3 is installed
OR crash-kmp-default-7.1.8_k4.4.73_5-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
kernel-default-4.4.180-94.107 is installed
OR kernel-default-base-4.4.180-94.107 is installed
OR kernel-default-devel-4.4.180-94.107 is installed
OR kernel-default-kgraft-4.4.180-94.107 is installed
OR kernel-default-man-4.4.180-94.107 is installed
OR kernel-devel-4.4.180-94.107 is installed
OR kernel-macros-4.4.180-94.107 is installed
OR kernel-source-4.4.180-94.107 is installed
OR kernel-syms-4.4.180-94.107 is installed
OR kgraft-patch-4_4_180-94_107-default-1-4.3 is installed
OR kgraft-patch-SLE12-SP3_Update_29-1-4.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
cups-1.7.5-20.29 is installed
OR cups-client-1.7.5-20.29 is installed
OR cups-libs-1.7.5-20.29 is installed
OR cups-libs-32bit-1.7.5-20.29 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND Package Information
cups-1.7.5-20.17 is installed
OR cups-client-1.7.5-20.17 is installed
OR cups-libs-1.7.5-20.17 is installed
OR cups-libs-32bit-1.7.5-20.17 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 6 is installed
AND Package Information
openstack-ironic-4.2.3~a0~dev14-1 is installed
OR openstack-ironic-api-4.2.3~a0~dev14-1 is installed
OR openstack-ironic-conductor-4.2.3~a0~dev14-1 is installed
OR python-ironic-4.2.3~a0~dev14-1 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 7 is installed
AND Package Information
xen-4.7.6_02-43.36 is installed
OR xen-doc-html-4.7.6_02-43.36 is installed
OR xen-libs-4.7.6_02-43.36 is installed
OR xen-libs-32bit-4.7.6_02-43.36 is installed
OR xen-tools-4.7.6_02-43.36 is installed
OR xen-tools-domU-4.7.6_02-43.36 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed
AND Package Information
libexif-0.6.22-8.9 is installed
OR libexif12-0.6.22-8.9 is installed
OR libexif12-32bit-0.6.22-8.9 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND Package Information
libsystemd0-228-150.82 is installed
OR libsystemd0-32bit-228-150.82 is installed
OR libudev-devel-228-150.82 is installed
OR libudev1-228-150.82 is installed
OR libudev1-32bit-228-150.82 is installed
OR systemd-228-150.82 is installed
OR systemd-32bit-228-150.82 is installed
OR systemd-bash-completion-228-150.82 is installed
OR systemd-sysvinit-228-150.82 is installed
OR udev-228-150.82 is installed
|