Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2018:1295-1 Important: libvirt Denial Of Service Fix

suse
Calendar Grey May 15, 2018
Dist Suse Esm H88
Crucial SUSE Security Patch for libvirt tackles severe concerns and implements remedies for various weaknesses.
An update that solves three vulnerabilities and has 5 fixes is now available

Summary

This update for libvirt fixes the following issues: Security issues fixed: - CVE-2017-5715: Spectre fixes for libvirt (bsc#1079869, bsc#1088147, bsc#1087887). - CVE-2018-1064: Avoid denial of service reading from QEMU guest agent (bsc#1083625). - CVE-2018-5748: Avoid denial of service reading from QEMU monitor (bsc#1076500). Bug fixes: - bsc#1025340: Use xend for nodeGetFreeMemory API. - bsc#960742: Allow read access to script directories in libvirtd AppArmor profile. - bsc#936233: Introduce qemuDomainDefCheckABIStability. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP3-LTSS:

References

#1025340 #1076500 #1079869 #1083625 #1087887

#1088147 #936233 #960742

Cross- CVE-2017-5715 CVE-2018-1064 CVE-2018-5748

Affected Products:

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-5715.html

https://www.suse.com/security/cve/CVE-2018-1064.html

https://www.suse.com/security/cve/CVE-2018-5748.html

https://bugzilla.suse.com/1025340

https://bugzilla.suse.com/1076500

https://bugzilla.suse.com/1079869

https://bugzilla.suse.com/1083625

https://bugzilla.suse.com/1087887

https://bugzilla.suse.com/1088147

https://bugzilla.suse.com/936233

https://bugzilla.suse.com/960742

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1295-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here