Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2016:1560-1 Important Update For Qemu OOB Access Issues

suse
Calendar Grey June 13, 2016
Scroller Suse
SUSE has issued a Security Update that resolves 37 vulnerabilities in qemu. Ensure your system is updated for enhanced security.
An update that solves 37 vulnerabilities and has two fixes An update that solves 37 vulnerabilities and has two fixes An update that solves 37 vulnerabilities and has two fixes is ...

Summary

qemu was updated to fix 37 security issues. These security issues were fixed: - CVE-2016-4439: Avoid OOB access in 53C9X emulation (bsc#980711) - CVE-2016-4441: Avoid OOB access in 53C9X emulation (bsc#980723) - CVE-2016-4952: Avoid OOB access in Vmware PV SCSI emulation (bsc#981266) - CVE-2015-8817: Avoid OOB access in PCI DMA I/O (bsc#969121) - CVE-2015-8818: Avoid OOB access in PCI DMA I/O (bsc#969122) - CVE-2016-3710: Fixed VGA emulation based OOB access with potential for guest escape (bsc#978158) - CVE-2016-3712: Fixed VGa emulation based DOS and OOB read access exploit (bsc#978160) - CVE-2016-4037: Fixed USB ehci based DOS (bsc#976109) - CVE-2016-2538: Fixed potential OOB access in USB net device emulation (bsc#967969) - CVE-2016-2841: Fixed OOB access / hang in ne2000 emulation (bsc#969350)

References

#886378 #895528 #901508 #928393 #934069 #940929

#944463 #947159 #958491 #958917 #959005 #959386

#960334 #960708 #960725 #960835 #961332 #961333

#961358 #961556 #961691 #962320 #963782 #964413

#967969 #969121 #969122 #969350 #970036 #970037

#975128 #975136 #975700 #976109 #978158 #978160

#980711 #980723 #981266

Cross- CVE-2014-3615 CVE-2014-3689 CVE-2014-9718

CVE-2015-3214 CVE-2015-5239 CVE-2015-5745

CVE-2015-7295 CVE-2015-7549 CVE-2015-8504

CVE-2015-8558 CVE-2015-8567 CVE-2015-8568

CVE-2015-8613 CVE-2015-8619 CVE-2015-8743

CVE-2015-8744 CVE-2015-8745 CVE-2015-8817

CVE-2015-8818 CVE-2016-1568 CVE-2016-1714

CVE-2016-1922 CVE-2016-1981 CVE-2016-2198

CVE-2016-2538 CVE-2016-2841 CVE-2016-2857

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1560-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.