Oval Definition:oval:org.opensuse.security:def:63651
Revision Date:2020-12-01Version:1
Title:Security update for qemu (Moderate)
Description:

This update for qemu fixes the following issues:

Security issues fixed:

- CVE-2018-10839: Fixed NE2000 NIC emulation support that is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS (bsc#1110910). - CVE-2018-15746: Fixed qemu-seccomp.c that might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread (bsc#1106222). - CVE-2018-17958: Fixed a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used (bsc#1111006). - CVE-2018-17962: Fixed a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used (bsc#1111010). - CVE-2018-17963: Fixed qemu_deliver_packet_iov in net/net.c that accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. (bsc#1111013) - CVE-2018-18849: Fixed an out of bounds memory access issue that was found in the LSI53C895A SCSI Host Bus Adapter emulation while writing a message in lsi_do_msgin. It could occur during migration if the 'msg_len' field has an invalid value. A user/process could use this flaw to crash the Qemu process resulting in DoS (bsc#1114422). - CVE-2018-16847: Fixed an out of bounds r/w buffer access in cmb operations (bsc#1114529).

Non-security issue fixed:

- Fixed a condition when retry logic does not have been executed in case of data transmit failure or connection hungup (bsc#1108474).
Family:unixClass:patch
Status:Reference(s):1038425
1040973
1068873
1088424
1097599
1097600
1106222
1108474
1109175
1109176
1109299
1110910
1111006
1111010
1111013
1114422
1114529
1115364
1117513
1124847
1131055
1136085
1139924
1141093
1142684
1146648
1156146
1159856
1159858
1159860
1160250
1160251
1166484
1169573
1169574
1169576
1169580
1174773
1177895
1177943
CVE-2017-1000126
CVE-2017-9239
CVE-2018-10839
CVE-2018-12264
CVE-2018-12265
CVE-2018-15746
CVE-2018-16847
CVE-2018-17229
CVE-2018-17230
CVE-2018-17282
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-19108
CVE-2018-19607
CVE-2018-9305
CVE-2019-0199
CVE-2019-0221
CVE-2019-10072
CVE-2019-13050
CVE-2019-13114
CVE-2019-14818
CVE-2019-15691
CVE-2019-15692
CVE-2019-15693
CVE-2019-15694
CVE-2019-15695
CVE-2020-11758
CVE-2020-11760
CVE-2020-11763
CVE-2020-11764
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14798
CVE-2020-14803
CVE-2020-16116
CVE-2020-1760
CVE-2020-27153
openSUSE-SU-2020:0087-1
openSUSE-SU-2020:0482-1
openSUSE-SU-2020:1183-2
openSUSE-SU-2020:1880-1
SUSE-SU-2018:4185-1
SUSE-SU-2019:0128-1
SUSE-SU-2019:1866-1
SUSE-SU-2019:2480-1
SUSE-SU-2019:3032-1
SUSE-SU-2020:0962-1
SUSE-SU-2020:1292-1
SUSE-SU-2020:3310-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • ark-20.04.2-lp152.2.3 is installed
  • OR ark-lang-20.04.2-lp152.2.3 is installed
  • OR libkerfuffle18-18.12.3-lp151.2.4 is installed
  • OR libkerfuffle20-20.04.2-lp152.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • bluez-5.48-lp152.12.6 is installed
  • OR bluez-auto-enable-devices-5.48-lp152.12.6 is installed
  • OR bluez-cups-5.48-lp152.12.6 is installed
  • OR bluez-devel-5.48-lp152.12.6 is installed
  • OR bluez-devel-32bit-5.48-lp152.12.6 is installed
  • OR bluez-test-5.48-lp152.12.6 is installed
  • OR libbluetooth3-5.48-lp152.12.6 is installed
  • OR libbluetooth3-32bit-5.48-lp152.12.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • qemu-2.11.2-5.5 is installed
  • OR qemu-arm-2.11.2-5.5 is installed
  • OR qemu-block-curl-2.11.2-5.5 is installed
  • OR qemu-block-iscsi-2.11.2-5.5 is installed
  • OR qemu-block-rbd-2.11.2-5.5 is installed
  • OR qemu-block-ssh-2.11.2-5.5 is installed
  • OR qemu-guest-agent-2.11.2-5.5 is installed
  • OR qemu-ipxe-1.0.0+-5.5 is installed
  • OR qemu-kvm-2.11.2-5.5 is installed
  • OR qemu-lang-2.11.2-5.5 is installed
  • OR qemu-ppc-2.11.2-5.5 is installed
  • OR qemu-s390-2.11.2-5.5 is installed
  • OR qemu-seabios-1.11.0-5.5 is installed
  • OR qemu-sgabios-8-5.5 is installed
  • OR qemu-tools-2.11.2-5.5 is installed
  • OR qemu-vgabios-1.11.0-5.5 is installed
  • OR qemu-x86-2.11.2-5.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.281-43.44 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.281-43.44 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.281-43.44 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.281-43.44 is installed
  • BACK