Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE 12-SP2: SUSE-SU-2017:0625-1 Critical: QEMU DoS And Escalation Risks

suse
Calendar Grey March 7, 2017
Dist Suse Esm H88
Ubuntu launched a significant upgrade for libvirt addressing 12 vulnerabilities and improving overall safety with several enhancements.
An update that solves 15 vulnerabilities and has four fixes An update that solves 15 vulnerabilities and has four fixes An update that solves 15 vulnerabilities and has four fixes ...

Summary

This update for qemu fixes several issues. These security issues were fixed: - CVE-2017-5898: The CCID Card device emulator support was vulnerable to an integer overflow flaw allowing a privileged user to crash the Qemu process on the host resulting in DoS (bsc#1023907). - CVE-2017-5857: The Virtio GPU Device emulator support was vulnerable to a host memory leakage issue allowing a guest user to leak host memory resulting in DoS (bsc#1023073). - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access,

References

#1014702 #1015169 #1016779 #1017081 #1017084

#1020491 #1020589 #1020928 #1021129 #1021195

#1021481 #1022541 #1023004 #1023053 #1023073

#1023907 #1024972 #1026583 #977027

Cross- CVE-2016-10028 CVE-2016-10029 CVE-2016-10155

CVE-2016-9921 CVE-2016-9922 CVE-2017-2615

CVE-2017-2620 CVE-2017-5525 CVE-2017-5526

CVE-2017-5552 CVE-2017-5578 CVE-2017-5667

CVE-2017-5856 CVE-2017-5857 CVE-2017-5898

Affected Products:

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2016-10028.html

https://www.suse.com/security/cve/CVE-2016-10029.html

https://www.suse.com/security/cve/CVE-2016-10155.html

https://www.suse.com/security/cve/CVE-2016-9921.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0625-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here