Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Security Update: 2018:4147-1 Moderate qemu DoS Issue Fix

opensuse
Calendar Grey December 16, 2018
Dist Opensuse Esm H88
Fedora rolls out a significant security patch for docker, addressing five vulnerabilities and reinforcing overall system safety.
An update that solves 6 vulnerabilities and has one errata is now available.

Description

This update for qemu fixes the following issues:

Security issues fixed:

- CVE-2018-10839: Fixed NE2000 NIC emulation support that is vulnerable to

an integer overflow, which could lead to buffer overflow issue. It could

occur when receiving packets over the network. A user inside guest could

use this flaw to crash the Qemu process resulting in DoS (bsc#1110910).

- CVE-2018-15746: Fixed qemu-seccomp.c that might allow local OS guest

users to cause a denial of service (guest crash) by leveraging

mishandling of the seccomp policy for threads other than the main thread

(bsc#1106222).

- CVE-2018-17958: Fixed a Buffer Overflow in rtl8139_do_receive in

hw/net/rtl8139.c because an incorrect integer data type is used

(bsc#1111006).

- CVE-2018-17962: Fixed a Buffer Overflow in pcnet_receive in

hw/net/pcnet.c because an incorrect integer data type is used

(bsc#1111010).

- CVE-2018-17963: Fixed qemu_deliver_packet_iov in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1563=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

qemu-linux-user-2.9.1-50.1

qemu-linux-user-debuginfo-2.9.1-50.1

qemu-linux-user-debugsource-2.9.1-50.1

- openSUSE Leap 42.3 (x86_64):

qemu-2.9.1-50.1

qemu-arm-2.9.1-50.1

qemu-arm-debuginfo-2.9.1-50.1

qemu-block-curl-2.9.1-50.1

qemu-block-curl-debuginfo-2.9.1-50.1

qemu-block-dmg-2.9.1-50.1

qemu-block-dmg-debuginfo-2.9.1-50.1

qemu-block-iscsi-2.9.1-50.1

qemu-block-iscsi-debuginfo-2.9.1-50.1

qemu-block-rbd-2.9.1-50.1

qemu-block-rbd-debuginfo-2.9.1-50.1

qemu-block-ssh-2.9.1-50.1

qemu-block-ssh-debuginfo-2.9.1-50.1

qemu-debugsource-2.9.1-50.1

qemu-extra-2.9.1-50.1

qemu-extra-debuginfo-2.9.1-50.1

qemu-guest-agent-2.9.1-50.1

qemu-guest-agent-debuginfo-2.9.1-50.1

qemu-ksm-2.9.1-50.1

qemu-kvm-2.9.1-50.1

qemu-lang-2.9.1-50.1

qemu-ppc-2.9.1-50.1

qemu-ppc-debuginfo-2.9.1-50.1

qemu-s390-2.9.1-50.1

qemu-s390-debuginfo-2.9.1-50.1

qemu-testsuite-2.9.1-50.1

qemu-tools-2.9.1-50.1

qemu-tools-debuginfo-2.9.1-50.1

qemu-x86-2.9.1-50.1

qemu-x86-debuginfo-2.9.1-50.1

- openSUSE Leap 42.3 (noarch):

qemu-ipxe-1....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-10839.html

https://www.suse.com/security/cve/CVE-2018-15746.html

https://www.suse.com/security/cve/CVE-2018-17958.html

https://www.suse.com/security/cve/CVE-2018-17962.html

https://www.suse.com/security/cve/CVE-2018-17963.html

https://www.suse.com/security/cve/CVE-2018-18849.html

https://bugzilla.suse.com/1100408

https://bugzilla.suse.com/1106222

https://bugzilla.suse.com/1110910

https://bugzilla.suse.com/1111006

https://bugzilla.suse.com/1111010

https://bugzilla.suse.com/1111013

https://bugzilla.suse.com/1114422

--

Announcement ID: openSUSE-SU-2018:4147-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here