Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2022:0210-1 Low Severity: Fixes Qemu DoS and Null Pointer Issues

suse
Calendar Grey January 27, 2022
Scroller Suse
SUSE has issued a security patch for qemu addressing severe vulnerabilities; comprehensive information on the associated risks and guidance on applying the updates are provided.
An update that fixes two vulnerabilities is now available

Summary

This update for qemu fixes the following issues: - CVE-2020-13253: Fixed an OOB access that could crash the guest resulting in DoS (bsc#1172033) - CVE-2021-20196: Fixed null pointer dereference that may lead to guest crash (bsc#1181361). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Micro 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2022-210=1 Package List: - SUSE Linux Enterprise Micro 5.0 (aarch64 x86_64): qemu-4.2.1-11.34.2 qemu-debuginfo-4.2.1-11.34.2 qemu-debugsource-4.2.1-11.34.2 qemu-tools-4.2.1-11.34.2 qemu-tools-debuginfo-4.2.1-11.34.2 - SUSE Linux Enterprise Micro 5.0 (aarch64):

References

#1172033 #1181361

Cross- CVE-2020-13253 CVE-2021-20196

CVSS scores:

CVE-2020-13253 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2020-13253 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CVE-2021-20196 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CVE-2021-20196 (SUSE): 3.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L

Affected Products:

SUSE Linux Enterprise Micro 5.0

https://www.suse.com/security/cve/CVE-2020-13253.html

https://www.suse.com/security/cve/CVE-2021-20196.html

https://bugzilla.suse.com/1172033

https://bugzilla.suse.com/1181361

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0210-1
Rating: low

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.