Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2016:0010-1 Important: kvm DoS And Buffer Overflow Fixes

suse
Calendar Grey January 4, 2016
Scroller Suse
SUSE Security Notice: kvm advisory ID SUSE-SU-2016:0010-2 tackles critical vulnerabilities and issues.
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

This update for kvm fixes the following issues: Security issues fixed: - CVE-2015-7512: The receive packet size is now checked in the emulated pcnet driver, eliminating buffer overflow and potential security issue by malicious guest systems. (bsc#957162) - CVE-2015-8345: A infinite loop in processing command block list was fixed that could be exploit by malicious guest systems (bsc#956829). Other bugs fixed: - To assist users past the migration incompatibility discussed in bsc#950590 (restore migration compatibility with SLE11 SP3 and SLE12, at the unfortunate expense to prior SLE11 SP4 kvm release compatability when a virtio-net device is used), print a message which references the support document TID 7017048. See https://www.suse.com/support/kb/

References

#947164 #950590 #953187 #956829 #957162

Cross- CVE-2015-7512 CVE-2015-8345

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Desktop 11-SP4

https://www.suse.com/security/cve/CVE-2015-7512.html

https://www.suse.com/security/cve/CVE-2015-8345.html

https://bugzilla.suse.com/show_bug.cgi?id=947164

https://bugzilla.suse.com/show_bug.cgi?id=950590

https://bugzilla.suse.com/show_bug.cgi?id=953187

https://bugzilla.suse.com/show_bug.cgi?id=956829

https://bugzilla.suse.com/show_bug.cgi?id=957162

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0010-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.