Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux Enterprise 15-SP1: 2020:2237-1 Important: Libvirt DoS Issue

suse
Calendar Grey August 14, 2020
Dist Suse Esm H88
SUSE has rolled out a security update addressing a severe vulnerability in libvirt, delivering essential patches along with crucial information to protect systems.
An update that solves one vulnerability and has four fixes is now available

Summary

This update for libvirt fixes the following issues: - CVE-2020-14339: Don't leak /dev/mapper/control into QEMU. Use ioctl's to obtain the dependency tree of disks and drop use of libdevmapper. - bsc#1161883, bsc#1174458 - qemu: Setup emulator thread and cpuset.mems before exec - bsc#1171946 - libxl: Normalize MAC address in device conf on netdev hotplug - bsc#1172052 - spec: Use a functional requires instead of explicit version requires for the new memory-related libxl APIs - bsc#1167007 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1:

References

#1161883 #1167007 #1171946 #1172052 #1174458

Cross- CVE-2020-14339

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2020-14339.html

https://bugzilla.suse.com/1161883

https://bugzilla.suse.com/1167007

https://bugzilla.suse.com/1171946

https://bugzilla.suse.com/1172052

https://bugzilla.suse.com/1174458

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2237-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here