Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2021:1942-1 Important: QEMU Security Update For Buffer Overflow

suse
Calendar Grey June 10, 2021
Scroller Suse
SUSE Security Update for OpenSSH addresses 12 vulnerabilities. Major updates improve user safety and operational efficiency.
An update that solves 14 vulnerabilities and has three fixes is now available

Summary

This update for qemu fixes the following issues: - Switch method of splitting off hw-s390x-virtio-gpu-ccw.so as a module to what was accepted upstream (bsc#1181103) - Fix OOB access in sdhci interface (CVE-2020-17380, bsc#1175144, CVE-2020-25085, bsc#1176681, CVE-2021-3409, bsc#1182282) - Fix potential privilege escalation in virtiofsd tool (CVE-2021-20263, bsc#1183373) - Fix OOB access (stack overflow) in rtl8139 NIC emulation (CVE-2021-3416, bsc#1182968) - Fix heap overflow in MSIx emulation (CVE-2020-27821, bsc#1179686) - Fix package scripts to not use hard coded paths for temporary working directories and log files (bsc#1182425) - QEMU BIOS fails to read stage2 loader on s390x (bsc#1186290) - For the record, these issues are fixed in this package already. Most are

References

#1149813 #1163019 #1175144 #1175534 #1176681

#1178683 #1178935 #1179477 #1179484 #1179686

#1181103 #1182282 #1182425 #1182968 #1182975

#1183373 #1186290

Cross- CVE-2019-15890 CVE-2020-14364 CVE-2020-17380

CVE-2020-25085 CVE-2020-25707 CVE-2020-25723

CVE-2020-27821 CVE-2020-29129 CVE-2020-29130

CVE-2020-8608 CVE-2021-20263 CVE-2021-3409

CVE-2021-3416 CVE-2021-3419

CVSS scores:

CVE-2019-15890 (SUSE): 5.8 CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

CVE-2020-14364 (NVD) : 5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

CVE-2020-14364 (SUSE): 5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

CVE-2020-17380 (NVD) : 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CVE-2020-17380 (SUSE): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1942-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.