Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:2877-1 Important: qemu DoS and Buffer Overflow Issues

suse
Calendar Grey October 7, 2020
Dist Suse Esm H88
SUSE has released a security patch addressing severe vulnerabilities in qemu that pose risks to system integrity and reliability.
An update that solves four vulnerabilities and has two fixes is now available

Summary

This update for qemu fixes the following issues: - CVE-2020-14364: Fixed an OOB access while processing USB packets (bsc#1175441,bsc#1176494). - CVE-2020-16092: Fixed a denial of service in packet processing of various emulated NICs (bsc#1174641). - CVE-2020-15863: Fixed a buffer overflow in the XGMAC device (bsc#1174386). - CVE-2020-24352: Fixed an out-of-bounds read/write in ati-vga device emulation in ati_2d_blt (bsc#1175370). - Allow to IPL secure guests with -no-reboot (bsc#1174863) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP2:

References

#1174386 #1174641 #1174863 #1175370 #1175441

#1176494

Cross- CVE-2020-14364 CVE-2020-15863 CVE-2020-16092

CVE-2020-24352

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2020-14364.html

https://www.suse.com/security/cve/CVE-2020-15863.html

https://www.suse.com/security/cve/CVE-2020-16092.html

https://www.suse.com/security/cve/CVE-2020-24352.html

https://bugzilla.suse.com/1174386

https://bugzilla.suse.com/1174641

https://bugzilla.suse.com/1174863

https://bugzilla.suse.com/1175370

https://bugzilla.suse.com/1175441

https://bugzilla.suse.com/1176494

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2877-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here