Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

SUSE Linux 11-SP4: Advisory 2017:1135-1 Major KVM Escalation and DoS Risk

suse
Calendar Grey April 28, 2017
Dist Suse Esm H88
SUSE Security Advisory: critical kernel patch addresses 12 vulnerabilities impacting SUSE Linux Enterprise Server.
An update that solves 10 vulnerabilities and has two fixes An update that solves 10 vulnerabilities and has two fixes An update that solves 10 vulnerabilities and has two fixes is ...

Summary

This update for kvm fixes several issues. These security issues were fixed: - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access, possibly leading to information disclosure or privilege escalation (bsc#1023004) - CVE-2016-9776: The ColdFire Fast Ethernet Controller emulator support was vulnerable to an infinite loop issue while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could have used this issue to crash the Qemu process on the host leading to DoS

References

#1013285 #1014109 #1014111 #1014702 #1015048

#1015169 #1016779 #1021129 #1023004 #1023053

#1023907 #1024972

Cross- CVE-2016-10155 CVE-2016-9776 CVE-2016-9907

CVE-2016-9911 CVE-2016-9921 CVE-2016-9922

CVE-2017-2615 CVE-2017-2620 CVE-2017-5856

CVE-2017-5898

Affected Products:

SUSE Linux Enterprise Server 11-SP4

https://www.suse.com/security/cve/CVE-2016-10155.html

https://www.suse.com/security/cve/CVE-2016-9776.html

https://www.suse.com/security/cve/CVE-2016-9907.html

https://www.suse.com/security/cve/CVE-2016-9911.html

https://www.suse.com/security/cve/CVE-2016-9921.html

https://www.suse.com/security/cve/CVE-2016-9922.html

https://www.suse.com/security/cve/CVE-2017-2615.html

https://www.suse.com/security/cve/CVE-2017-2620.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1135-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here