Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2016:0020-1 Important: Kvm Buffer Overflow And Loop Fix

suse
Calendar Grey January 5, 2016
Scroller Suse
Patch release for KVM tackles significant concerns, encompassing stack overflow and endless loop flaws.
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

This update for kvm fixes the following issues: Security issues fixed: - CVE-2015-7512: The receive packet size is now checked in the emulated pcnet driver, eliminating buffer overflow and potential security issue by malicious guest systems. (bsc#957162) - CVE-2015-8345: A infinite loop in processing command block list was fixed that could be exploit by malicious guest systems (bsc#956829). Bugs fixed: - Fix cases of wrong clock values in kvmclock timekeeping (bsc#947164 and bsc#953187) - Enforce pxe rom sizes to ensure migration compatibility. (bsc#950590) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP3: zypper in -t patch slessp3-kvm-12294=1

References

#947164 #950590 #953187 #956829 #957162

Cross- CVE-2015-7512 CVE-2015-8345

Affected Products:

SUSE Linux Enterprise Server 11-SP3

SUSE Linux Enterprise Desktop 11-SP3

https://www.suse.com/security/cve/CVE-2015-7512.html

https://www.suse.com/security/cve/CVE-2015-8345.html

https://bugzilla.suse.com/show_bug.cgi?id=947164

https://bugzilla.suse.com/show_bug.cgi?id=950590

https://bugzilla.suse.com/show_bug.cgi?id=953187

https://bugzilla.suse.com/show_bug.cgi?id=956829

https://bugzilla.suse.com/show_bug.cgi?id=957162

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0020-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.