Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:1042-1 Moderate: Libvirt Remote DoS And Info Leak

suse
Calendar Grey April 26, 2019
Dist Suse Esm H88
Caution: This email originated from outside the organization. Do not click links or open attachments
An update that solves two vulnerabilities and has three fixes is now available

Summary

This update for libvirt fixes the following issues: Security issues fixed: - CVE-2019-3840: Fixed a null pointer dereference vulnerability in virJSONValueObjectHasKey function which could have resulted in a remote denial of service via the guest agent (bsc#1127458). - CVE-2019-3886: Fixed an information leak which allowed to retrieve the guest hostname under readonly mode (bsc#1131595). Other issue addressed: - cpu: add Skylake-Server and Skylake-Server-IBRS CPU models (FATE#327261, bsc#1131955) - libxl: save current memory value after successful balloon (bsc#1120813). - libxl: support Xen's max_grant_frames setting with maxGrantFrames attribute on the xenbus controller (bsc#1126325). - conf: add new 'xenbus' controller type Patch Instructions:

References

#1120813 #1126325 #1127458 #1131595 #1131955

Cross- CVE-2019-3840 CVE-2019-3886

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2019-3840.html

https://www.suse.com/security/cve/CVE-2019-3886.html

https://bugzilla.suse.com/1120813

https://bugzilla.suse.com/1126325

https://bugzilla.suse.com/1127458

https://bugzilla.suse.com/1131595

https://bugzilla.suse.com/1131955

Announcement ID: SUSE-SU-2019:1042-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here