Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2017:0661-1 Important: Qemu Memory Leakage and Privilege Escalation

suse
Calendar Grey March 10, 2017
Dist Suse Esm H88
Fedora announces critical patch for libvirt, addressing 9 security flaws and bolstering overall system integrity.
An update that solves 11 vulnerabilities and has two fixes An update that solves 11 vulnerabilities and has two fixes An update that solves 11 vulnerabilities and has two fixes is ...

Summary

This update for qemu fixes several issues. These security issues were fixed: - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access, possibly leading to information disclosure or privilege escalation (bsc#1023004) - CVE-2017-5856: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to a memory leakage issue allowing a privileged user to leak host memory resulting in DoS (bsc#1023053) - CVE-2016-9776: The ColdFire Fast Ethernet Controller emulator support

References

#1013285 #1014109 #1014111 #1014702 #1015048

#1015169 #1016779 #1021129 #1022541 #1023004

#1023053 #1023907 #1024972

Cross- CVE-2016-10155 CVE-2016-9776 CVE-2016-9907

CVE-2016-9911 CVE-2016-9921 CVE-2016-9922

CVE-2017-2615 CVE-2017-2620 CVE-2017-5667

CVE-2017-5856 CVE-2017-5898

Affected Products:

SUSE Linux Enterprise Server for SAP 12

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2016-10155.html

https://www.suse.com/security/cve/CVE-2016-9776.html

https://www.suse.com/security/cve/CVE-2016-9907.html

https://www.suse.com/security/cve/CVE-2016-9911.html

https://www.suse.com/security/cve/CVE-2016-9921.html

https://www.suse.com/security/cve/CVE-2016-9922.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0661-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here