Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE 15-SP2 Important Security Update for Qemu Fixes Multiple Issues

suse
Calendar Grey April 16, 2021
Scroller Suse
A crucial release for SUSE qemu resolves 12 vulnerabilities, improving security measures and bolstering overall system resilience.
An update that solves 15 vulnerabilities and has two fixes is now available

Summary

This update for qemu fixes the following issues: - CVE-2020-12829: Fix OOB access in sm501 device emulation (bsc#1172385) - CVE-2020-25723: Fix use-after-free in usb xhci packet handling (bsc#1178934) - CVE-2020-25084: Fix use-after-free in usb ehci packet handling (bsc#1176673) - CVE-2020-25625: Fix infinite loop (DoS) in usb hcd-ohci emulation (bsc#1176684) - CVE-2020-25624: Fix OOB access in usb hcd-ohci emulation (bsc#1176682) - CVE-2020-27617: Fix guest triggerable assert in shared network handling code (bsc#1178174) - CVE-2020-28916: Fix infinite loop (DoS) in e1000e device emulation (bsc#1179468) - CVE-2020-29443: Fix OOB access in atapi emulation (bsc#1181108) - CVE-2020-27821: Fix heap overflow in MSIx emulation (bsc#1179686)

References

#1172385 #1173612 #1176673 #1176682 #1176684

#1178174 #1178400 #1178934 #1179466 #1179467

#1179468 #1179686 #1181108 #1182425 #1182577

#1182968 #1184064

Cross- CVE-2020-12829 CVE-2020-15469 CVE-2020-25084

CVE-2020-25624 CVE-2020-25625 CVE-2020-25723

CVE-2020-27616 CVE-2020-27617 CVE-2020-27821

CVE-2020-28916 CVE-2020-29129 CVE-2020-29130

CVE-2020-29443 CVE-2021-20257 CVE-2021-3416

CVSS scores:

CVE-2020-12829 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2020-12829 (SUSE): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE-2020-15469 (NVD) : 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CVE-2020-15469 (SUSE): 6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

CVE-2020-25084 (NVD) : 3.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1243-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.