Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE 15.2: 2021:0600-1 High Severity: QEMU DoS and OOB Issues

opensuse
Calendar Grey April 23, 2021
Dist Opensuse Esm H88
Updates addressing 15 vulnerabilities, including significant DoS and OOB in QEMU, accompanied by comprehensive installation instructions.
An update that solves 15 vulnerabilities and has two fixes is now available

Description

This update for qemu fixes the following issues:

- CVE-2020-12829: Fix OOB access in sm501 device emulation (bsc#1172385)

- CVE-2020-25723: Fix use-after-free in usb xhci packet handling

(bsc#1178934)

- CVE-2020-25084: Fix use-after-free in usb ehci packet handling

(bsc#1176673)

- CVE-2020-25625: Fix infinite loop (DoS) in usb hcd-ohci emulation

(bsc#1176684)

- CVE-2020-25624: Fix OOB access in usb hcd-ohci emulation (bsc#1176682)

- CVE-2020-27617: Fix guest triggerable assert in shared network handling

code (bsc#1178174)

- CVE-2020-28916: Fix infinite loop (DoS) in e1000e device emulation

(bsc#1179468)

- CVE-2020-29443: Fix OOB access in atapi emulation (bsc#1181108)

- CVE-2020-27821: Fix heap overflow in MSIx emulation (bsc#1179686)

- CVE-2020-15469: Fix null pointer deref. (DoS) in mmio ops (bsc#1173612)

- CVE-2021-20257: Fix infinite loop (DoS) in e1000 device emulation

(bsc#1182577)

- CVE-2021-3416: Fix OOB...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-600=1

Package List

- openSUSE Leap 15.2 (noarch):

qemu-ipxe-1.0.0+-lp152.9.12.1

qemu-microvm-4.2.1-lp152.9.12.1

qemu-seabios-1.12.1+-lp152.9.12.1

qemu-sgabios-8-lp152.9.12.1

qemu-vgabios-1.12.1+-lp152.9.12.1

- openSUSE Leap 15.2 (x86_64):

qemu-4.2.1-lp152.9.12.1

qemu-arm-4.2.1-lp152.9.12.1

qemu-arm-debuginfo-4.2.1-lp152.9.12.1

qemu-audio-alsa-4.2.1-lp152.9.12.1

qemu-audio-alsa-debuginfo-4.2.1-lp152.9.12.1

qemu-audio-pa-4.2.1-lp152.9.12.1

qemu-audio-pa-debuginfo-4.2.1-lp152.9.12.1

qemu-audio-sdl-4.2.1-lp152.9.12.1

qemu-audio-sdl-debuginfo-4.2.1-lp152.9.12.1

qemu-block-curl-4.2.1-lp152.9.12.1

qemu-block-curl-debuginfo-4.2.1-lp152.9.12.1

qemu-block-dmg-4.2.1-lp152.9.12.1

qemu-block-dmg-debuginfo-4.2.1-lp152.9.12.1

qemu-block-gluster-4.2.1-lp152.9.12.1

qemu-block-gluster-debuginfo-4.2.1-lp152.9.12.1

qemu-block-iscsi-4.2.1-lp152.9.12.1

qemu-block-iscsi-debuginfo-4.2.1-lp152.9.12.1

qemu-block-nfs-4.2.1-lp152.9.12.1

qemu-block-nfs-debuginfo-4.2.1-lp152.9.12.1

qemu-block-rbd-4.2.1-lp152.9.12.1

qemu-block-rbd-debuginfo-4.2.1-lp152.9.12.1

qe...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-12829.html

https://www.suse.com/security/cve/CVE-2020-15469.html

https://www.suse.com/security/cve/CVE-2020-25084.html

https://www.suse.com/security/cve/CVE-2020-25624.html

https://www.suse.com/security/cve/CVE-2020-25625.html

https://www.suse.com/security/cve/CVE-2020-25723.html

https://www.suse.com/security/cve/CVE-2020-27616.html

https://www.suse.com/security/cve/CVE-2020-27617.html

https://www.suse.com/security/cve/CVE-2020-27821.html

https://www.suse.com/security/cve/CVE-2020-28916.html

https://www.suse.com/security/cve/CVE-2020-29129.html

https://www.suse.com/security/cve/CVE-2020-29130.html

https://www.suse.com/security/cve/CVE-2020-29443.html

https://www.suse.com/security/cve/CVE-2021-20257.html

https://www.suse.com/security/cve/CVE-2021-3416.html

https://bugzilla.suse.com/1172385

https://bugzilla.suse.com/1173612

https://bugzilla.suse.com/1176673

https://bugzilla.suse.com/1176682

https://bugzilla.suse.com/1176684

https://bugzilla.suse.com/1178174

https://...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0600-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here