Oval Definition:oval:org.opensuse.security:def:56681
Revision Date:2020-12-01Version:1
Title:Security update for qemu (Moderate)
Description:

This update for qemu fixes the following issues:

Security issues fixed:

- CVE-2018-10839: Fixed NE2000 NIC emulation support that is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS (bsc#1110910). - CVE-2018-15746: Fixed qemu-seccomp.c that might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread (bsc#1106222). - CVE-2018-17958: Fixed a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used (bsc#1111006). - CVE-2018-17962: Fixed a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used (bsc#1111010). - CVE-2018-17963: Fixed qemu_deliver_packet_iov in net/net.c that accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. (bsc#1111013) - CVE-2018-18849: Fixed an out of bounds memory access issue that was found in the LSI53C895A SCSI Host Bus Adapter emulation while writing a message in lsi_do_msgin. It could occur during migration if the 'msg_len' field has an invalid value. A user/process could use this flaw to crash the Qemu process resulting in DoS (bsc#1114422).

Non-security issues fixed:

- Improving disk performance for qemu on xen (bsc#1100408)
Family:unixClass:patch
Status:Reference(s):1007869
1007870
1007871
1012964
1027519
1042419
1056865
1058565
1058622
1058624
1063671
1064016
1064392
1065892
1066471
1066472
1072834
1078431
1080634
1080635
1080662
1087251
1087252
1089152
1089635
1090820
1090822
1090823
1100408
1101644
1101645
1101651
1101656
1106222
1110910
1111006
1111010
1111013
1112142
1112143
1112144
1112146
1112147
1112152
1112153
1114422
1119947
1124937
1152856
1154212
1168874
798458
817781
857188
858676
858677
867943
941939
955131
982178
992534
CVE-2009-2473
CVE-2009-2474
CVE-2011-4971
CVE-2013-0179
CVE-2013-7239
CVE-2013-7290
CVE-2013-7291
CVE-2015-4734
CVE-2015-4803
CVE-2015-4805
CVE-2015-4806
CVE-2015-4810
CVE-2015-4835
CVE-2015-4840
CVE-2015-4842
CVE-2015-4843
CVE-2015-4844
CVE-2015-4860
CVE-2015-4871
CVE-2015-4872
CVE-2015-4882
CVE-2015-4883
CVE-2015-4893
CVE-2015-4902
CVE-2015-4903
CVE-2015-4911
CVE-2015-5006
CVE-2016-5118
CVE-2016-5384
CVE-2016-8704
CVE-2016-8705
CVE-2016-8706
CVE-2016-9079
CVE-2017-12150
CVE-2017-12151
CVE-2017-12163
CVE-2017-13080
CVE-2017-15649
CVE-2017-9951
CVE-2018-10471
CVE-2018-10472
CVE-2018-10839
CVE-2018-13785
CVE-2018-15746
CVE-2018-16435
CVE-2018-16884
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-2562
CVE-2018-2612
CVE-2018-2622
CVE-2018-2640
CVE-2018-2665
CVE-2018-2668
CVE-2018-2938
CVE-2018-2940
CVE-2018-2952
CVE-2018-2973
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3214
CVE-2018-3639
CVE-2018-7540
CVE-2018-7541
CVE-2018-7542
CVE-2018-8897
CVE-2019-2894
CVE-2019-2933
CVE-2019-2945
CVE-2019-2949
CVE-2019-2958
CVE-2019-2962
CVE-2019-2964
CVE-2019-2973
CVE-2019-2978
CVE-2019-2981
CVE-2019-2983
CVE-2019-2987
CVE-2019-2988
CVE-2019-2989
CVE-2019-2992
CVE-2019-2999
CVE-2019-6212
CVE-2019-6215
CVE-2019-6216
CVE-2019-6217
CVE-2019-6226
CVE-2019-6227
CVE-2019-6229
CVE-2019-6233
CVE-2019-6234
CVE-2020-6821
CVE-2020-6822
CVE-2020-6825
CVE-2020-6827
CVE-2020-6828
SUSE-SU-2015:2268-1
SUSE-SU-2016:1570-1
SUSE-SU-2016:2190-1
SUSE-SU-2016:3048-1
SUSE-SU-2017:2971-1
SUSE-SU-2017:3130-1
SUSE-SU-2018:0697-1
SUSE-SU-2018:0778-1
SUSE-SU-2018:1184-1
SUSE-SU-2018:4129-1
SUSE-SU-2019:0049-1
SUSE-SU-2019:0511-1
SUSE-SU-2019:3084-1
SUSE-SU-2020:0978-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND libXRes1-1.2.0-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • python-requests-2.20.1-lp151.2.3 is installed
  • OR python-requests-test-2.20.1-lp151.2.3 is installed
  • OR python2-requests-2.20.1-lp151.2.3 is installed
  • OR python2-requests-test-2.20.1-lp151.2.3 is installed
  • OR python3-requests-2.20.1-lp151.2.3 is installed
  • OR python3-requests-test-2.20.1-lp151.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • qemu-2.9.1-6.22 is installed
  • OR qemu-block-curl-2.9.1-6.22 is installed
  • OR qemu-ipxe-1.0.0+-6.22 is installed
  • OR qemu-kvm-2.9.1-6.22 is installed
  • OR qemu-seabios-1.10.2-6.22 is installed
  • OR qemu-sgabios-8-6.22 is installed
  • OR qemu-tools-2.9.1-6.22 is installed
  • OR qemu-vgabios-1.10.2-6.22 is installed
  • OR qemu-x86-2.9.1-6.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr2.0-4 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr2.0-4 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr2.0-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_67-60_64_18-default-12-2 is installed
  • OR kgraft-patch-3_12_67-60_64_18-xen-12-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_9-12-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libneon27-0.30.0-3 is installed
  • OR libneon27-32bit-0.30.0-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20180425-13.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • openslp-2.0.0-18.17 is installed
  • OR openslp-32bit-2.0.0-18.17 is installed
  • OR openslp-server-2.0.0-18.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.25-38.23 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.25-38.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • MozillaFirefox-52.2.0esr-108 is installed
  • OR MozillaFirefox-translations-52.2.0esr-108 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libpython2_7-1_0-2.7.13-28.31 is installed
  • OR libpython2_7-1_0-32bit-2.7.13-28.31 is installed
  • OR python-2.7.13-28.31 is installed
  • OR python-32bit-2.7.13-28.31 is installed
  • OR python-base-2.7.13-28.31 is installed
  • OR python-base-32bit-2.7.13-28.31 is installed
  • OR python-curses-2.7.13-28.31 is installed
  • OR python-demo-2.7.13-28.31 is installed
  • OR python-devel-2.7.13-28.31 is installed
  • OR python-doc-2.7.13-28.31 is installed
  • OR python-doc-pdf-2.7.13-28.31 is installed
  • OR python-gdbm-2.7.13-28.31 is installed
  • OR python-idle-2.7.13-28.31 is installed
  • OR python-tk-2.7.13-28.31 is installed
  • OR python-xml-2.7.13-28.31 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • MozillaFirefox-60.9.0-109.86 is installed
  • OR MozillaFirefox-translations-common-60.9.0-109.86 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • gstreamer-1.8.3-9 is installed
  • OR gstreamer-lang-1.8.3-9 is installed
  • OR gstreamer-utils-1.8.3-9 is installed
  • OR libgstreamer-1_0-0-1.8.3-9 is installed
  • OR libgstreamer-1_0-0-32bit-1.8.3-9 is installed
  • OR typelib-1_0-Gst-1_0-1.8.3-9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • ctdb-4.2.4-28.21 is installed
  • OR libdcerpc-binding0-4.2.4-28.21 is installed
  • OR libdcerpc-binding0-32bit-4.2.4-28.21 is installed
  • OR libdcerpc0-4.2.4-28.21 is installed
  • OR libdcerpc0-32bit-4.2.4-28.21 is installed
  • OR libgensec0-4.2.4-28.21 is installed
  • OR libgensec0-32bit-4.2.4-28.21 is installed
  • OR libndr-krb5pac0-4.2.4-28.21 is installed
  • OR libndr-krb5pac0-32bit-4.2.4-28.21 is installed
  • OR libndr-nbt0-4.2.4-28.21 is installed
  • OR libndr-nbt0-32bit-4.2.4-28.21 is installed
  • OR libndr-standard0-4.2.4-28.21 is installed
  • OR libndr-standard0-32bit-4.2.4-28.21 is installed
  • OR libndr0-4.2.4-28.21 is installed
  • OR libndr0-32bit-4.2.4-28.21 is installed
  • OR libnetapi0-4.2.4-28.21 is installed
  • OR libnetapi0-32bit-4.2.4-28.21 is installed
  • OR libregistry0-4.2.4-28.21 is installed
  • OR libsamba-credentials0-4.2.4-28.21 is installed
  • OR libsamba-credentials0-32bit-4.2.4-28.21 is installed
  • OR libsamba-hostconfig0-4.2.4-28.21 is installed
  • OR libsamba-hostconfig0-32bit-4.2.4-28.21 is installed
  • OR libsamba-passdb0-4.2.4-28.21 is installed
  • OR libsamba-passdb0-32bit-4.2.4-28.21 is installed
  • OR libsamba-util0-4.2.4-28.21 is installed
  • OR libsamba-util0-32bit-4.2.4-28.21 is installed
  • OR libsamdb0-4.2.4-28.21 is installed
  • OR libsamdb0-32bit-4.2.4-28.21 is installed
  • OR libsmbclient-raw0-4.2.4-28.21 is installed
  • OR libsmbclient-raw0-32bit-4.2.4-28.21 is installed
  • OR libsmbclient0-4.2.4-28.21 is installed
  • OR libsmbclient0-32bit-4.2.4-28.21 is installed
  • OR libsmbconf0-4.2.4-28.21 is installed
  • OR libsmbconf0-32bit-4.2.4-28.21 is installed
  • OR libsmbldap0-4.2.4-28.21 is installed
  • OR libsmbldap0-32bit-4.2.4-28.21 is installed
  • OR libtevent-util0-4.2.4-28.21 is installed
  • OR libtevent-util0-32bit-4.2.4-28.21 is installed
  • OR libwbclient0-4.2.4-28.21 is installed
  • OR libwbclient0-32bit-4.2.4-28.21 is installed
  • OR samba-4.2.4-28.21 is installed
  • OR samba-32bit-4.2.4-28.21 is installed
  • OR samba-client-4.2.4-28.21 is installed
  • OR samba-client-32bit-4.2.4-28.21 is installed
  • OR samba-doc-4.2.4-28.21 is installed
  • OR samba-libs-4.2.4-28.21 is installed
  • OR samba-libs-32bit-4.2.4-28.21 is installed
  • OR samba-winbind-4.2.4-28.21 is installed
  • OR samba-winbind-32bit-4.2.4-28.21 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND memcached-1.4.39-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND squid-3.5.21-26.23 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND python-SQLAlchemy-1.2.10-3.3 is installed
  • BACK