Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

SUSE: 2021:1241-1 Important: Qemu DoS and Buffer Overflow Fixes

suse
Calendar Grey April 16, 2021
Scroller Suse
Solutions for severe vulnerabilities within qemu impacting SUSE platforms with significant patches rolled out. Safeguard your infrastructure immediately.
An update that solves 24 vulnerabilities and has three fixes is now available

Summary

This update for qemu fixes the following issues: - Fix OOB access in sm501 device emulation (CVE-2020-12829, bsc#1172385) - Fix OOB access possibility in MegaRAID SAS 8708EM2 emulation (CVE-2020-13362, bsc#1172383) - Fix use-after-free in usb xhci packet handling (CVE-2020-25723, bsc#1178934) - Fix use-after-free in usb ehci packet handling (CVE-2020-25084, bsc#1176673) - Fix OOB access in usb hcd-ohci emulation (CVE-2020-25624, bsc#1176682) - Fix infinite loop (DoS) in usb hcd-ohci emulation (CVE-2020-25625, bsc#1176684) - Fix guest triggerable assert in shared network handling code (CVE-2020-27617, bsc#1178174) - Fix infinite loop (DoS) in e1000e device emulation (CVE-2020-28916, bsc#1179468) - Fix OOB access in atapi emulation (CVE-2020-29443, bsc#1181108)

References

#1112499 #1119115 #1172383 #1172384 #1172385

#1172386 #1172478 #1173612 #1174386 #1174641

#1175441 #1176673 #1176682 #1176684 #1178174

#1178934 #1179466 #1179467 #1179468 #1180523

#1181108 #1181639 #1181933 #1182137 #1182425

#1182577 #1182968

Cross- CVE-2020-11947 CVE-2020-12829 CVE-2020-13361

CVE-2020-13362 CVE-2020-13659 CVE-2020-13765

CVE-2020-14364 CVE-2020-15469 CVE-2020-15863

CVE-2020-16092 CVE-2020-25084 CVE-2020-25624

CVE-2020-25625 CVE-2020-25723 CVE-2020-27617

CVE-2020-28916 CVE-2020-29129 CVE-2020-29130

CVE-2020-29443 CVE-2021-20181 CVE-2021-20203

CVE-2021-20221 CVE-2021-20257 CVE-2021-3416

CVSS scores:

CVE-2020-11947 (NVD) : 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1241-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.