Oval Definition:oval:org.opensuse.security:def:79085
Revision Date:2017-09-11Version:1
Title:Security update for qemu (Important)
Description:

This update for qemu fixes the following issues:

Security issues fixed:

CVE-2017-10664: Fix DOS vulnerability in qemu-nbd (bsc#1046636) * CVE-2017-10806: Fix DOS from stack overflow in debug messages of usb redirection support (bsc#1047674) * CVE-2017-11334: Fix OOB access during DMA operation (bsc#1048902) * CVE-2017-11434: Fix OOB access parsing dhcp slirp options (bsc#1049381)

Following non-security issues were fixed:

- Postrequire acl for setfacl - Prerequire shadow for groupadd - The recent security fix for CVE-2017-11334 adversely affects Xen. Include two additional patches to make sure Xen is going to be OK. - Pre-add group kvm for qemu-tools (bsc#1011144) - Fixed a few more inaccuracies in the support docs. - Fix support docs to indicate ARM64 is now fully L3 supported in SLES 12 SP3. Apply a few additional clarifications in the support docs. (bsc#1050268) - Adjust to libvdeplug-devel package naming changes. - Fix migration with xhci (bsc#1048296) - Increase VNC delay to fix missing keyboard input events (bsc#1031692) - Remove build dependency package iasl used for seabios

Family:unixClass:patch
Status:Reference(s):1011144
1031692
1046636
1047674
1048296
1048902
1049381
1050268
CVE-2017-10664
CVE-2017-10806
CVE-2017-11334
CVE-2017-11434
SUSE-SU-2017:2416-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP3
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • qemu-2.9.0-6.3.1 is installed
  • OR qemu-block-curl-2.9.0-6.3.1 is installed
  • OR qemu-ipxe-1.0.0-6.3.1 is installed
  • OR qemu-kvm-2.9.0-6.3.1 is installed
  • OR qemu-seabios-1.10.2-6.3.1 is installed
  • OR qemu-sgabios-8-6.3.1 is installed
  • OR qemu-tools-2.9.0-6.3.1 is installed
  • OR qemu-vgabios-1.10.2-6.3.1 is installed
  • OR qemu-x86-2.9.0-6.3.1 is installed
  • BACK