Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

openSUSE Leap 15.1: 2020:0756-1 Moderate: qemu Use-After-Free Issue

opensuse
Calendar Grey June 2, 2020
Scroller Opensuse
openSUSE Security Update: Security update for qemu _________________________________________________
An update that solves one vulnerability and has two fixes is now available.

Description

This update for qemu fixes the following issues:

Security issue fixed:

- CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp

(bsc#1170940).

Non-security issues fixed:

- Fixed an issue where limiting the memory bandwidth was not possible

(bsc#1167816).

- Fixed the issue that s390x could not read IPL channel program when using

dasd as boot device (bsc#1158880).

- Miscellaneous fixes to the in-package support documentation.

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-756=1

Package List

- openSUSE Leap 15.1 (noarch):

qemu-ipxe-1.0.0+-lp151.7.15.2

qemu-seabios-1.12.0-lp151.7.15.2

qemu-sgabios-8-lp151.7.15.2

qemu-vgabios-1.12.0-lp151.7.15.2

- openSUSE Leap 15.1 (x86_64):

qemu-3.1.1.1-lp151.7.15.2

qemu-arm-3.1.1.1-lp151.7.15.2

qemu-arm-debuginfo-3.1.1.1-lp151.7.15.2

qemu-audio-alsa-3.1.1.1-lp151.7.15.2

qemu-audio-alsa-debuginfo-3.1.1.1-lp151.7.15.2

qemu-audio-oss-3.1.1.1-lp151.7.15.2

qemu-audio-oss-debuginfo-3.1.1.1-lp151.7.15.2

qemu-audio-pa-3.1.1.1-lp151.7.15.2

qemu-audio-pa-debuginfo-3.1.1.1-lp151.7.15.2

qemu-audio-sdl-3.1.1.1-lp151.7.15.2

qemu-audio-sdl-debuginfo-3.1.1.1-lp151.7.15.2

qemu-block-curl-3.1.1.1-lp151.7.15.2

qemu-block-curl-debuginfo-3.1.1.1-lp151.7.15.2

qemu-block-dmg-3.1.1.1-lp151.7.15.2

qemu-block-dmg-debuginfo-3.1.1.1-lp151.7.15.2

qemu-block-gluster-3.1.1.1-lp151.7.15.2

qemu-block-gluster-debuginfo-3.1.1.1-lp151.7.15.2

qemu-block-iscsi-3.1.1.1-lp151.7.15.2

qemu-block-iscsi-debuginfo-3.1.1.1-lp151.7.15.2

qemu-block-nfs-3.1.1.1-lp151.7.15.2

qemu-block-nfs-debuginfo-3.1.1.1-lp151...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-1983.html

https://bugzilla.suse.com/1158880

https://bugzilla.suse.com/1167816

https://bugzilla.suse.com/1170940

--

Announcement ID: openSUSE-SU-2020:0756-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.