Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

SUSE: 2021:1305-1 Important: QEMU DoS and OOB Access Issues

suse
Calendar Grey April 22, 2021
Scroller Suse
Resolves 21 vulnerabilities in qemu following critical SUSE Security Update. Information on applied patches, identified vulnerabilities, and steps for installation.
An update that solves 21 vulnerabilities and has one errata is now available

Summary

This update for qemu fixes the following issues: - Fix OOB access in sm501 device emulation (CVE-2020-12829, bsc#1172385) - Fix OOB access possibility in MegaRAID SAS 8708EM2 emulation (CVE-2020-13362 bsc#1172383) - Fix use-after-free in usb xhci packet handling (CVE-2020-25723, bsc#1178934) - Fix use-after-free in usb ehci packet handling (CVE-2020-25084, bsc#1176673) - Fix OOB access in usb hcd-ohci emulation (CVE-2020-25624, bsc#1176682) - Fix infinite loop (DoS) in usb hcd-ohci emulation (CVE-2020-25625, bsc#1176684) - Fix guest triggerable assert in shared network handling code (CVE-2020-27617, bsc#1178174) - Fix OOB access in atapi emulation (CVE-2020-29443, bsc#1181108) - Fix null pointer deref. (DoS) in mmio ops (CVE-2020-15469, bsc#1173612)

References

#1172383 #1172384 #1172385 #1172386 #1172478

#1173612 #1174386 #1174641 #1175441 #1176673

#1176682 #1176684 #1178174 #1178934 #1179467

#1180523 #1181108 #1181639 #1182137 #1182425

#1182577 #1182968

Cross- CVE-2020-11947 CVE-2020-12829 CVE-2020-13361

CVE-2020-13362 CVE-2020-13659 CVE-2020-13765

CVE-2020-14364 CVE-2020-15469 CVE-2020-15863

CVE-2020-16092 CVE-2020-25084 CVE-2020-25624

CVE-2020-25625 CVE-2020-25723 CVE-2020-27617

CVE-2020-29130 CVE-2020-29443 CVE-2021-20181

CVE-2021-20203 CVE-2021-20257 CVE-2021-3416

CVSS scores:

CVE-2020-11947 (NVD) : 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE-2020-11947 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2020-12829 (NVD) : 5.5 CVSS:3.1/AV:L/...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1305-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.