Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2021:1242-1 Important: QEMU DoS and Access Issues Fixed

suse
Calendar Grey April 16, 2021
Scroller Suse
Important announcement from SUSE tackling numerous concerns in qemu, featuring 21 solutions for security weaknesses.
An update that solves 21 vulnerabilities and has 5 fixes is now available

Summary

This update for qemu fixes the following issues: - Fix OOB access in sm501 device emulation (CVE-2020-12829, bsc#1172385) - Fix OOB access possibility in MegaRAID SAS 8708EM2 emulation (CVE-2020-13362 bsc#1172383) - Fix use-after-free in usb xhci packet handling (CVE-2020-25723, bsc#1178934) - Fix use-after-free in usb iehci packet handling (CVE-2020-25084, bsc#1176673) - Fix infinite loop (DoS) in usb hcd-ohci emulation (CVE-2020-25625, bsc#1176684) - Fix OOB access in usb hcd-ohci emulation (CVE-2020-25624, bsc#1176682) - Fix guest triggerable assert in shared network handling code (CVE-2020-27617, bsc#1178174) - Fix infinite loop (DoS) in e1000e device emulation (CVE-2020-28916, bsc#1179468) - Fix OOB access in atapi emulation (CVE-2020-29443, bsc#1181108)

References

#1172383 #1172385 #1172386 #1172478 #1173612

#1176673 #1176682 #1176684 #1178049 #1178174

#1178934 #1179466 #1179467 #1179468 #1179686

#1179725 #1179726 #1180523 #1181108 #1181639

#1181933 #1182137 #1182425 #1182577 #1182968

#1183979

Cross- CVE-2020-11947 CVE-2020-12829 CVE-2020-13362

CVE-2020-13659 CVE-2020-13765 CVE-2020-15469

CVE-2020-25084 CVE-2020-25624 CVE-2020-25625

CVE-2020-25723 CVE-2020-27617 CVE-2020-27821

CVE-2020-28916 CVE-2020-29129 CVE-2020-29130

CVE-2020-29443 CVE-2021-20181 CVE-2021-20203

CVE-2021-20221 CVE-2021-20257 CVE-2021-3416

CVSS scores:

CVE-2020-11947 (NVD) : 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE-2020-11947 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1242-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.