Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: Important KVM Security Fixes Released for 2018:0039-1 Update

suse
Calendar Grey January 8, 2018
Dist Suse Esm H88
Crucial Fedora patch for KVM fixes significant vulnerabilities and boosts overall system reliability. Ensure to install updates without delay.
An update that fixes two vulnerabilities is now available.

Summary

This update for kvm fixes the following issues: A security flaw mitigation has been applied: - CVE-2017-5715: QEMU was updated to allow passing through new MSR and CPUID flags from the host VM to the CPU, to allow enabling/disabling branch prediction features in the Intel CPU. (bsc#1068032) Also a security fix has been applied: - CVE-2017-2633: Fix various out of bounds access issues in the QEMU vnc infrastructure (bsc#1026612) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-kvm-13397=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-kvm-13397=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#1026612 #1068032

Cross- CVE-2017-2633 CVE-2017-5715

Affected Products:

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

https://www.suse.com/security/cve/CVE-2017-2633.html

https://www.suse.com/security/cve/CVE-2017-5715.html

https://bugzilla.suse.com/1026612

https://bugzilla.suse.com/1068032

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0039-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here