Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE 11-SP4 Security Advisory: 2016:2902-1 Important KVM Update

suse
Calendar Grey November 24, 2016
Scroller Suse
Patch set addresses 17 vulnerabilities in SUSE's KVM, delivering essential security updates and improvements that are now accessible.
An update that fixes 17 vulnerabilities is now available

Summary

This update for kvm fixes the following issues: - Address various security/stability issues * Fix OOB access in xlnx.xpx-ethernetlite emulation (CVE-2016-7161 bsc#1001151) * Fix OOB access in VMware SVGA emulation (CVE-2016-7170 bsc#998516) * Fix DOS in ColdFire Fast Ethernet Controller emulation (CVE-2016-7908 bsc#1002550) * Fix DOS in USB xHCI emulation (CVE-2016-8576 bsc#1003878) * Fix DOS in virtio-9pfs (CVE-2016-8578 bsc#1003894) * Fix DOS in virtio-9pfs (CVE-2016-9105 bsc#1007494) * Fix DOS in virtio-9pfs (CVE-2016-8577 bsc#1003893) * Plug data leak in virtio-9pfs interface (CVE-2016-9103 bsc#1007454) * Fix DOS in virtio-9pfs interface (CVE-2016-9102 bsc#1007450) * Fix DOS in virtio-9pfs (CVE-2016-9106 bsc#1007495) * Fix DOS in 16550A UART emulation (CVE-2016-8669 bsc#1004707)

References

#1001151 #1002550 #1002557 #1003878 #1003893

#1003894 #1004702 #1004707 #1006536 #1006538

#1007391 #1007450 #1007454 #1007493 #1007494

#1007495 #998516

Cross- CVE-2016-7161 CVE-2016-7170 CVE-2016-7908

CVE-2016-7909 CVE-2016-8576 CVE-2016-8577

CVE-2016-8578 CVE-2016-8667 CVE-2016-8669

CVE-2016-8909 CVE-2016-8910 CVE-2016-9101

CVE-2016-9102 CVE-2016-9103 CVE-2016-9104

CVE-2016-9105 CVE-2016-9106

Affected Products:

SUSE Linux Enterprise Server 11-SP4

https://www.suse.com/security/cve/CVE-2016-7161.html

https://www.suse.com/security/cve/CVE-2016-7170.html

https://www.suse.com/security/cve/CVE-2016-7908.html

https://www.suse.com/security/cve/CVE-2016-7909.html

https://www.suse.com/security/cve/CVE-2016-8576.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2902-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.