Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2021:2118-1 Critical: Buffer Overflow Vulnerability in OVMF

suse
Calendar Grey June 22, 2021
Scroller Suse
SUSE announces critical patch for ovmf resolving a memory leak vulnerability in enterprise software.
An update that contains security fixes can now be installed

Summary

This update for ovmf fixes the following issues: - Fixed a possible buffer overflow in IScsiDxe (bsc#1186151) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2021-2118=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 x86_64): ovmf-202008-10.8.1 ovmf-tools-202008-10.8.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (noarch): qemu-ovmf-x86_64-202008-10.8.1 qemu-uefi-aarch64-202008-10.8.1

References

#1186151

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP3

https://bugzilla.suse.com/1186151

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:2118-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.