Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

openSUSE: 2023:3721-1 Important Qemu Security Update for DoS

opensuse
Calendar Grey September 21, 2023
Scroller Opensuse
A critical security advisory for QEMU on openSUSE has been issued to mitigate significant vulnerabilities; update to version 7.1.0 or later immediately
This update for qemu fixes the following issues: CVE-2022-26354: Fixed a memory leak due to a missing virtqueue detach on error

Description

This update for qemu fixes the following issues:

* CVE-2022-26354: Fixed a memory leak due to a missing virtqueue detach on

error. (bsc#1198712)

* CVE-2021-3929: Fixed an use-after-free in nvme DMA reentrancy issue.

(bsc#1193880)

* CVE-2023-0330: Fixed a stack overflow due to a DMA reentrancy issue.

(bsc#1207205)

* CVE-2020-13754: Fixed a DoS due to an OOB access during mmio operations.

(bsc#1172382)

* CVE-2023-3354: Fixed a remote unauthenticated DoS due to an improper I/O

watch removal in VNC TLS handshake. (bsc#1212850)

* CVE-2023-3180: Fixed a heap buffer overflow in

virtio_crypto_sym_op_helper(). (bsc#1213925)

* CVE-2021-3638: Fixed an out-of-bounds write due to an inconsistent check in

ati_2d_blt(). (bsc#1188609)

* CVE-2021-3750: Fixed an use-after-free in DMA reentrancy issue.

(bsc#1190011)

* CVE-2023-2861: Fixed improper access control on special files in 9pfs

(bsc#1212968).

* CVE-2022-1050: Fixed use-after-free issue...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3721=1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3721=1

* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2

zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-3721=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP2

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-3721=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* qemu-s390-debuginfo-4.2.1-150200.79.1

* qemu-s390-4.2.1-150200.79.1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64

x86_64)

* qemu-block-rbd-debuginfo-4.2.1-150200.79.1

* qemu-debugsource-4.2.1-150200.79.1

* qemu-block-iscsi-debuginfo-4.2.1-150200.79.1

* qemu-lang-4.2.1-150200.79.1

* qemu-4.2.1-150200.79.1

* qemu-block-iscsi-4.2.1-150200.79.1

* qemu-block-curl-debuginfo-4.2.1-150200.79.1

* qemu-tools-4.2.1-150200.79.1

* qemu-block-ssh-debuginfo-4.2.1-150200.79.1

* qemu-block-curl-4.2.1-150200.79.1

* qemu-guest-agent-debuginfo-4.2.1-150200.79.1

* qemu-block-ssh-4.2.1-150200.79.1

* qemu-guest-agent-4.2.1-150200.79.1

* qemu-tools-debuginfo-4.2.1-150200.79.1

* qemu-ui-spice-app-4.2.1-150200.79.1

* qemu-ui-spice-app-debuginfo-4.2.1-150200.79.1

* qemu-block-rbd-4.2.1-150200.79.1

* qemu-debuginfo-4.2.1-150200.79.1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

(aarch64)

* qemu-arm-4.2.1-150200.79.1

*...

Read the Full Advisory

References

* #1172382

* #1188609

* #1190011

* #1193880

* #1197653

* #1198712

* #1207205

* #1212850

* #1212968

* #1213925

* #1215311

## References:

* https://www.suse.com/security/cve/CVE-2020-13754.html

* https://www.suse.com/security/cve/CVE-2021-3638.html

* https://www.suse.com/security/cve/CVE-2021-3750.html

* https://www.suse.com/security/cve/CVE-2021-3929.html

* https://www.suse.com/security/cve/CVE-2022-1050.html

* https://www.suse.com/security/cve/CVE-2022-26354.html

* https://www.suse.com/security/cve/CVE-2023-0330.html

* https://www.suse.com/security/cve/CVE-2023-2861.html

* https://www.suse.com/security/cve/CVE-2023-3180.html

* https://www.suse.com/security/cve/CVE-2023-3354.html

* https://bugzilla.suse.com/show_bug.cgi?id=1172382

* https://bugzilla.suse.com/show_bug.cgi?id=1188609

* https://bugzilla.suse.com/show_bug.cgi?id=1190011

* https://bugzilla.suse.com/show_bug.cgi?id=1193880

* https://bugzilla.suse.com/show_bug.cgi?id=1197653

* https://bugzilla.suse.com/show_bug.cgi?id=1198712

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:3721-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.