Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:3039-1 Important: libvirt Security Update Details

suse
Calendar Grey October 27, 2020
Dist Suse Esm H88
SUSE releases a vital security patch for libvirt to rectify significant vulnerabilities. Make sure your systems are updated and protected.
An update that solves two vulnerabilities and has three fixes is now available

Summary

This update for libvirt fixes the following issues: - CVE-2020-15708: Added a note to libvirtd.conf about polkit auth in SUSE distros (bsc#1174955). - CVE-2020-25637: Fixed a double free in qemuAgentGetInterfaces() (bsc#1177155). - qemu: Adjust max memlock on mdev hotplug (bsc#1177480). - Xen: Don't add dom0 twice on driver reload (bsc#1176430). - Fixed an issue where building was failing (bsc#1175574). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-3039=1 - SUSE Linux Enterprise Server 12-SP5:

References

#1174955 #1175574 #1176430 #1177155 #1177480

Cross- CVE-2020-15708 CVE-2020-25637

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2020-15708.html

https://www.suse.com/security/cve/CVE-2020-25637.html

https://bugzilla.suse.com/1174955

https://bugzilla.suse.com/1175574

https://bugzilla.suse.com/1176430

https://bugzilla.suse.com/1177155

https://bugzilla.suse.com/1177480

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3039-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here