Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2018:3973-2 Moderate: Resolved qemu DoS Vulnerabilities

suse
Calendar Grey April 27, 2019
Dist Suse Esm H88
New patch released for qemu targeting various bugs and improving SUSE safety measures. Check out the recent updates here.
An update that fixes 6 vulnerabilities is now available

Summary

This update for qemu fixes the following issues: Security issues fixed: - CVE-2018-10839: Fixed NE2000 NIC emulation support that is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS (bsc#1110910). - CVE-2018-15746: Fixed qemu-seccomp.c that might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread (bsc#1106222). - CVE-2018-17958: Fixed a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used (bsc#1111006). - CVE-2018-17962: Fixed a Buffer Overflow in pcnet_receive in

References

#1106222 #1110910 #1111006 #1111010 #1111013

#1114422

Cross- CVE-2018-10839 CVE-2018-15746 CVE-2018-17958

CVE-2018-17962 CVE-2018-17963 CVE-2018-18849

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

https://www.suse.com/security/cve/CVE-2018-10839.html

https://www.suse.com/security/cve/CVE-2018-15746.html

https://www.suse.com/security/cve/CVE-2018-17958.html

https://www.suse.com/security/cve/CVE-2018-17962.html

https://www.suse.com/security/cve/CVE-2018-17963.html

https://www.suse.com/security/cve/CVE-2018-18849.html

https://bugzilla.suse.com/1106222

https://bugzilla.suse.com/1110910

https://bugzilla.suse.com/1111006

https://bugzilla.suse.com/1111010

https://bugzilla.suse.com/1111013

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3973-2
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here