Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2017:3084-1 Important: KVM DoS and Escalation Risks

suse
Calendar Grey November 24, 2017
Dist Suse Esm H88
SUSE Security Patch for kvm tackles 33 potential threats with 7 resolutions, reinforcing system integrity and trust.
An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is ...

Summary

This update for kvm fixes several issues. These security issues were fixed: - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024972) - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access, possibly leading to information disclosure or privilege escalation (bsc#1023004) - CVE-2016-9776: The ColdFire Fast Ethernet Controller emulator support was vulnerable to an infinite loop issue while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could have used this issue to crash the Qemu process on the host leading to DoS

References

#1013285 #1014109 #1014111 #1014702 #1015048

#1016779 #1020427 #1021129 #1021741 #1023004

#1023053 #1023907 #1024972 #1025109 #1028184

#1028656 #1030624 #1031051 #1034044 #1034866

#1034908 #1035406 #1035950 #1037242 #1038396

#1039495 #1042159 #1042800 #1042801 #1043296

#1045035 #1046636 #1047674 #1048902 #1049381

#1049785 #1056334 #1057585 #1062069 #1063122

Cross- CVE-2016-10155 CVE-2016-9602 CVE-2016-9603

CVE-2016-9776 CVE-2016-9907 CVE-2016-9911

CVE-2016-9921 CVE-2016-9922 CVE-2017-10664

CVE-2017-10806 CVE-2017-11334 CVE-2017-11434

CVE-2017-13672 CVE-2017-14167 CVE-2017-15038

CVE-2017-15289 CVE-2017-2615 CVE-2017-2620

CVE-2017-5579 CVE-2017-5856 CVE-2017-5898

CVE-2017-5973 CVE-2017-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:3084-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here