This update for kvm fixes several issues. These security issues were fixed: - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access, possibly leading to information disclosure or privilege escalation (bsc#1023004) - CVE-2016-9776: The ColdFire Fast Ethernet Controller emulator support was vulnerable to an infinite loop issue while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could have used this issue to crash the Qemu process on the host leading to DoS
#1013285 #1014109 #1014111 #1014702 #1015048
#1016779 #1020427 #1021129 #1021741 #1023004
#1023053 #1023907 #1024972 #1025109 #1028184
#1028656 #1030624 #1031051 #1034044 #1034866
#1034908 #1035406 #1035950 #1037242 #1038396
#1039495 #1042159 #1042800 #1042801 #1043296
#1045035 #1046636 #1047674 #1048902 #1049381
#1049785 #1056334 #1057585 #1062069 #1063122
Cross- CVE-2016-10155 CVE-2016-9602 CVE-2016-9603
CVE-2016-9776 CVE-2016-9907 CVE-2016-9911
CVE-2016-9921 CVE-2016-9922 CVE-2017-10664
CVE-2017-10806 CVE-2017-11334 CVE-2017-11434
CVE-2017-13672 CVE-2017-14167 CVE-2017-15038
CVE-2017-15289 CVE-2017-2615 CVE-2017-2620
CVE-2017-5579 CVE-2017-5856 CVE-2017-5898
CVE-2017-5973 CVE-2017-...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.