Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

openSUSE Leap 15.2: 2021:1043-1 Moderate: QEMU Security Risks

opensuse
Calendar Grey July 13, 2021
Scroller Opensuse
Critical updates for Fedora's KVM address 12 vulnerabilities, focusing on buffer overflows and privilege escalations.
An update that solves 14 vulnerabilities, contains one feature and has 5 fixes is now available

Description

This update for qemu fixes the following issues:

Security issues fixed:

- CVE-2021-3546: Fix out-of-bounds write in virgl_cmd_get_capset

(bsc#1185981)

- CVE-2021-3544: Fix memory leaks found in the virtio vhost-user GPU

device (bsc#1186010)

- CVE-2021-3545: Fix information disclosure due to uninitialized memory

read (bsc#1185990)

- CVE-2020-25085: Fix out-of-bounds access issue while doing multi block

SDMA (bsc#1176681)

- CVE-2020-10756: Fix out-of-bounds read information disclosure in

icmp6_send_echoreply(bsc#1172380)

- For the record, these issues are fixed in this package already. Most are

alternate references to previously mentioned issues: (CVE-2019-15890,

bsc#1149813, CVE-2020-8608, bsc#1163019, CVE-2020-14364, bsc#1175534,

CVE-2020-25707, bsc#1178683, CVE-2020-25723, bsc#1178935,

CVE-2020-29130, bsc#1179477, CVE-2020-29129, bsc#1179484,

CVE-2021-20257, bsc#1182846, CVE-2021-3419, bsc#1182975)

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1043=1

Package List

- openSUSE Leap 15.2 (x86_64):

qemu-4.2.1-lp152.9.16.2

qemu-arm-4.2.1-lp152.9.16.2

qemu-arm-debuginfo-4.2.1-lp152.9.16.2

qemu-audio-alsa-4.2.1-lp152.9.16.2

qemu-audio-alsa-debuginfo-4.2.1-lp152.9.16.2

qemu-audio-pa-4.2.1-lp152.9.16.2

qemu-audio-pa-debuginfo-4.2.1-lp152.9.16.2

qemu-audio-sdl-4.2.1-lp152.9.16.2

qemu-audio-sdl-debuginfo-4.2.1-lp152.9.16.2

qemu-block-curl-4.2.1-lp152.9.16.2

qemu-block-curl-debuginfo-4.2.1-lp152.9.16.2

qemu-block-dmg-4.2.1-lp152.9.16.2

qemu-block-dmg-debuginfo-4.2.1-lp152.9.16.2

qemu-block-gluster-4.2.1-lp152.9.16.2

qemu-block-gluster-debuginfo-4.2.1-lp152.9.16.2

qemu-block-iscsi-4.2.1-lp152.9.16.2

qemu-block-iscsi-debuginfo-4.2.1-lp152.9.16.2

qemu-block-nfs-4.2.1-lp152.9.16.2

qemu-block-nfs-debuginfo-4.2.1-lp152.9.16.2

qemu-block-rbd-4.2.1-lp152.9.16.2

qemu-block-rbd-debuginfo-4.2.1-lp152.9.16.2

qemu-block-ssh-4.2.1-lp152.9.16.2

qemu-block-ssh-debuginfo-4.2.1-lp152.9.16.2

qemu-debuginfo-4.2.1-lp152.9.16.2

qemu-debugsource-4.2.1-lp152.9.16.2

qemu-extra-4.2.1-lp152.9.16.2

qemu-extra-d...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-15890.html

https://www.suse.com/security/cve/CVE-2020-10756.html

https://www.suse.com/security/cve/CVE-2020-14364.html

https://www.suse.com/security/cve/CVE-2020-25085.html

https://www.suse.com/security/cve/CVE-2020-25707.html

https://www.suse.com/security/cve/CVE-2020-25723.html

https://www.suse.com/security/cve/CVE-2020-29129.html

https://www.suse.com/security/cve/CVE-2020-29130.html

https://www.suse.com/security/cve/CVE-2020-8608.html

https://www.suse.com/security/cve/CVE-2021-20257.html

https://www.suse.com/security/cve/CVE-2021-3419.html

https://www.suse.com/security/cve/CVE-2021-3544.html

https://www.suse.com/security/cve/CVE-2021-3545.html

https://www.suse.com/security/cve/CVE-2021-3546.html

https://bugzilla.suse.com/1149813

https://bugzilla.suse.com/1163019

https://bugzilla.suse.com/1172380

https://bugzilla.suse.com/1175534

https://bugzilla.suse.com/1176681

https://bugzilla.suse.com/1178683

https://bugzilla.suse.com/1178935

https://bugzilla.suse.com/117947...

Read the Full Advisory

Announcement ID: openSUSE-SU-2021:1043-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.