Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE: 2021:1240-1 Important: QEMU Out Of Bounds Security Advisory

suse
Calendar Grey April 16, 2021
Scroller Suse
Crucial SUSE patch for qemu resolves several vulnerabilities, improving both security and overall stability of the system.
An update that solves 22 vulnerabilities and has one errata is now available

Summary

This update for qemu fixes the following issues: - Fix OOB access in sm501 device emulation (CVE-2020-12829, bsc#1172385) - Fix OOB access possibility in MegaRAID SAS 8708EM2 emulation (CVE-2020-13362 bsc#1172383) - Fix use-after-free in usb xhci packet handling (CVE-2020-25723, bsc#1178934) - Fix use-after-free in usb ehci packet handling (CVE-2020-25084, bsc#1176673) - Fix OOB access in usb hcd-ohci emulation (CVE-2020-25624, bsc#1176682) - Fix infinite loop (DoS) in usb hcd-ohci emulation (CVE-2020-25625, bsc#1176684) - Fix guest triggerable assert in shared network handling code (CVE-2020-27617, bsc#1178174) - Fix infinite loop (DoS) in e1000e device emulation (CVE-2020-28916, bsc#1179468) - Fix OOB access in atapi emulation (CVE-2020-29443, bsc#1181108)

References

#1172383 #1172384 #1172385 #1172386 #1172478

#1173612 #1174386 #1174641 #1175441 #1176673

#1176682 #1176684 #1178174 #1178934 #1179467

#1179468 #1180523 #1181108 #1181639 #1182137

#1182425 #1182577 #1182968

Cross- CVE-2020-11947 CVE-2020-12829 CVE-2020-13361

CVE-2020-13362 CVE-2020-13659 CVE-2020-13765

CVE-2020-14364 CVE-2020-15469 CVE-2020-15863

CVE-2020-16092 CVE-2020-25084 CVE-2020-25624

CVE-2020-25625 CVE-2020-25723 CVE-2020-27617

CVE-2020-28916 CVE-2020-29130 CVE-2020-29443

CVE-2021-20181 CVE-2021-20203 CVE-2021-20257

CVE-2021-3416

CVSS scores:

CVE-2020-11947 (NVD) : 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE-2020-11947 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1240-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.