Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE 12-SP4: 2019:2956-1 Important: qemu Use-After-Free and DoS

suse
Calendar Grey November 12, 2019
Dist Suse Esm H88
SUSE Security Notification: Urgent resolution for qemu security flaws featuring several significant updates.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for qemu fixes the following issues: - Remove a backslash "\" escape character from 80-qemu-ga.rules (bsc#1153358) Unlike sles 15 or newer guests, The udev rule file of qemu guest agent in sles 12 sp4 or newer guest only needs one escape character. - Fix use-after-free in slirp (CVE-2018-20126 bsc#1119991) - Fix potential DOS in lsi scsi controller emulation (CVE-2019-12068 bsc#1146873) - Expose taa-no "feature", indicating CPU does not have the TSX Async Abort vulnerability. (CVE-2019-11135 bsc#1152506) - Expose pschange-mc-no "feature", indicating CPU does not have the page size change machine check vulnerability (CVE-2018-12207 bsc#1155812) - Patch queue updated from SLE12-SP4 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1119991 #1146873 #1152506 #1153358 #1155812

Cross- CVE-2018-12207 CVE-2018-20126 CVE-2019-11135

CVE-2019-12068

Affected Products:

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

https://www.suse.com/security/cve/CVE-2018-12207.html

https://www.suse.com/security/cve/CVE-2018-20126.html

https://www.suse.com/security/cve/CVE-2019-11135.html

https://www.suse.com/security/cve/CVE-2019-12068.html

https://bugzilla.suse.com/1119991

https://bugzilla.suse.com/1146873

https://bugzilla.suse.com/1152506

https://bugzilla.suse.com/1153358

https://bugzilla.suse.com/1155812

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2956-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here