Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:1502-1 Moderate Security Fix for QEMU Use-After-Free Issue

suse
Calendar Grey May 29, 2020
Dist Suse Esm H88
Ubuntu Security Update released for qemu tackling a significant vulnerability. Ensure your system is protected by applying the newest updates and corrections.
An update that solves one vulnerability and has two fixes is now available

Summary

This update for qemu fixes the following issues: Security issue fixed: - CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940). Non-security issues fixed: - Fixed an issue where limiting the memory bandwidth was not possible (bsc#1167816). - Fixed the issue that s390x could not read IPL channel program when using dasd as boot device (bsc#1158880). - Miscellaneous fixes to the in-package support documentation. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-1502=1

References

#1158880 #1167816 #1170940

Cross- CVE-2020-1983

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2020-1983.html

https://bugzilla.suse.com/1158880

https://bugzilla.suse.com/1167816

https://bugzilla.suse.com/1170940

Announcement ID: SUSE-SU-2020:1502-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here