Oval Definition:oval:org.opensuse.security:def:67373
Revision Date:2021-02-19Version:1
Title:Security update for qemu (Important)
Description:

This update for qemu fixes the following issues:

- Fixed potential privilege escalation in virtfs (CVE-2021-20181 bsc#1182137) - Fixed out-of-bound access in iscsi (CVE-2020-11947 bsc#1180523) - Fixed out-of-bound access in vmxnet3 emulation (CVE-2021-20203 bsc#1181639) - Fixed out-of-bound access in ARM interrupt handling (CVE-2021-20221 bsc#1181933) - Fixed vfio-pci device on s390 enters error state (bsc#1179717 bsc#1179719) - Fixed 'Failed to try-restart qemu-ga@.service' error while updating the qemu-guest-agent. (bsc#1178565) - Apply fixes to qemu scsi passthrough with respect to timeout and error conditions, including using more correct status codes. Add more qemu tracing which helped track down these issues (bsc#1178049)
Family:unixClass:patch
Status:Reference(s):1174157
1177158
1177943
1178049
1178565
1179717
1179719
1180523
1181639
1181933
1182137
CVE-2020-11947
CVE-2020-14355
CVE-2020-14556
CVE-2020-14577
CVE-2020-14578
CVE-2020-14579
CVE-2020-14581
CVE-2020-14583
CVE-2020-14593
CVE-2020-14621
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14798
CVE-2020-14803
CVE-2021-20181
CVE-2021-20203
CVE-2021-20221
SUSE-SU-2020:3070-1
SUSE-SU-2020:3460-1
Platform(s):SUSE Linux Enterprise Module for Legacy Software 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP3
SUSE Linux Enterprise Module for Server Applications 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy Software 15 SP2 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.272-3.42 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.272-3.42 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.272-3.42 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.272-3.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND Package Information
  • libspice-server-devel-0.14.2-3.3 is installed
  • OR libspice-server1-0.14.2-3.3 is installed
  • OR spice-0.14.2-3.3 is installed
  • BACK