This update for qemu fixes several issues. These security issues were fixed: - CVE-2017-5898: The CCID Card device emulator support was vulnerable to an integer overflow flaw allowing a privileged user to crash the Qemu process on the host resulting in DoS (bsc#1023907). - CVE-2017-5857: The Virtio GPU Device emulator support was vulnerable to a host memory leakage issue allowing a guest user to leak host memory resulting in DoS (bsc#1023073). - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access,
#1014702 #1015169 #1016779 #1017081 #1017084
#1020491 #1020589 #1020928 #1021129 #1021195
#1021481 #1022541 #1023004 #1023053 #1023073
#1023907 #1024972 #1026583 #977027
Cross- CVE-2016-10028 CVE-2016-10029 CVE-2016-10155
CVE-2016-9921 CVE-2016-9922 CVE-2017-2615
CVE-2017-2620 CVE-2017-5525 CVE-2017-5526
CVE-2017-5552 CVE-2017-5578 CVE-2017-5667
CVE-2017-5856 CVE-2017-5857 CVE-2017-5898
Affected Products:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
SUSE Linux Enterprise Server 12-SP2
SUSE Linux Enterprise Desktop 12-SP2
https://www.suse.com/security/cve/CVE-2016-10028.html
https://www.suse.com/security/cve/CVE-2016-10029.html
https://www.suse.com/security/cve/CVE-2016-10155.html
https://www.suse.com/security/cve/CVE-2016-9921.html
Get the latest Linux and open source security news straight to your inbox.