Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0357-1

Опубликовано: 23 янв. 2015
Источник: suse-cvrf

Описание

Security update for kvm and libvirt

This collective update for KVM and libvirt provides fixes for security and non-security issues.

kvm:

* Fix NULL pointer dereference because of uninitialized UDP socket. (bsc#897654, CVE-2014-3640) * Fix performance degradation after migration. (bsc#878350) * Fix potential image corruption due to missing FIEMAP_FLAG_SYNC flag in FS_IOC_FIEMAP ioctl. (bsc#908381) * Add validate hex properties for qdev. (bsc#852397) * Add boot option to do strict boot (bsc#900084) * Add query-command-line-options QMP command. (bsc#899144) * Fix incorrect return value of migrate_cancel. (bsc#843074) * Fix insufficient parameter validation during ram load. (bsc#905097, CVE-2014-7840) * Fix insufficient blit region checks in qemu/cirrus. (bsc#907805, CVE-2014-8106)

libvirt:

* Fix security hole with migratable flag in dumpxml. (bsc#904176, CVE-2014-7823) * Fix domain deadlock. (bsc#899484, CVE-2014-3657) * Use correct definition when looking up disk in qemu blkiotune. (bsc#897783, CVE-2014-3633) * Fix undefined symbol when starting virtlockd. (bsc#910145) * Add '-boot strict' to qemu's commandline whenever possible. (bsc#900084) * Add support for 'reboot-timeout' in qemu. (bsc#899144) * Increase QEMU's monitor timeout to 30sec. (bsc#911742) * Allow setting QEMU's migration max downtime any time. (bsc#879665)

Security Issues:

* CVE-2014-7823 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7823> * CVE-2014-3657 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3657> * CVE-2014-3633 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3633> * CVE-2014-3640 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3640> * CVE-2014-7840 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7840> * CVE-2014-8106 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8106>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
kvm-1.4.2-0.21.4
libvirt-1.0.5.9-0.19.3
libvirt-client-1.0.5.9-0.19.3
libvirt-client-32bit-1.0.5.9-0.19.3
libvirt-doc-1.0.5.9-0.19.3
libvirt-python-1.0.5.9-0.19.3
SUSE Linux Enterprise Server 11 SP3
kvm-1.4.2-0.21.4
libvirt-1.0.5.9-0.19.3
libvirt-client-1.0.5.9-0.19.3
libvirt-client-32bit-1.0.5.9-0.19.3
libvirt-doc-1.0.5.9-0.19.3
libvirt-lock-sanlock-1.0.5.9-0.19.3
libvirt-python-1.0.5.9-0.19.3
SUSE Linux Enterprise Server 11 SP3-TERADATA
kvm-1.4.2-0.21.4
libvirt-1.0.5.9-0.19.3
libvirt-client-1.0.5.9-0.19.3
libvirt-client-32bit-1.0.5.9-0.19.3
libvirt-doc-1.0.5.9-0.19.3
libvirt-lock-sanlock-1.0.5.9-0.19.3
libvirt-python-1.0.5.9-0.19.3
SUSE Linux Enterprise Server for SAP Applications 11 SP3
kvm-1.4.2-0.21.4
libvirt-1.0.5.9-0.19.3
libvirt-client-1.0.5.9-0.19.3
libvirt-client-32bit-1.0.5.9-0.19.3
libvirt-doc-1.0.5.9-0.19.3
libvirt-lock-sanlock-1.0.5.9-0.19.3
libvirt-python-1.0.5.9-0.19.3
SUSE Linux Enterprise Software Development Kit 11 SP3
libvirt-devel-1.0.5.9-0.19.3
libvirt-devel-32bit-1.0.5.9-0.19.3

Описание

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки

Описание

The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки

Описание

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки

Описание

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки

Описание

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки

Описание

Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kvm-1.4.2-0.21.4
SUSE Linux Enterprise Desktop 11 SP3:libvirt-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-1.0.5.9-0.19.3
SUSE Linux Enterprise Desktop 11 SP3:libvirt-client-32bit-1.0.5.9-0.19.3

Ссылки