Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0016-1

Опубликовано: 07 янв. 2020
Источник: suse-cvrf

Описание

Security update for virglrenderer

This update for virglrenderer fixes the following issues:

  • CVE-2019-18388: Fixed a null pointer dereference which could have led to denial of service (bsc#1159479).
  • CVE-2019-18390: Fixed an out of bound read which could have led to denial of service (bsc#1159478).
  • CVE-2019-18389: Fixed a heap buffer overflow which could have led to guest escape or denial of service (bsc#1159482).
  • CVE-2019-18391: Fixed a heap based buffer overflow which could have led to guest escape or denial of service (bsc#1159486).

Список пакетов

HPE Helion OpenStack 8
libvirglrenderer0-0.5.0-12.3.1
SUSE Enterprise Storage 5
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Desktop 12 SP4
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP3-BCL
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP4
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP5
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Software Development Kit 12 SP4
virglrenderer-devel-0.5.0-12.3.1
SUSE Linux Enterprise Software Development Kit 12 SP5
virglrenderer-devel-0.5.0-12.3.1
SUSE OpenStack Cloud 7
libvirglrenderer0-0.5.0-12.3.1
SUSE OpenStack Cloud 8
libvirglrenderer0-0.5.0-12.3.1
SUSE OpenStack Cloud Crowbar 8
libvirglrenderer0-0.5.0-12.3.1

Описание

A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.


Затронутые продукты
HPE Helion OpenStack 8:libvirglrenderer0-0.5.0-12.3.1
SUSE Enterprise Storage 5:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Desktop 12 SP4:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:libvirglrenderer0-0.5.0-12.3.1

Ссылки

Описание

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.


Затронутые продукты
HPE Helion OpenStack 8:libvirglrenderer0-0.5.0-12.3.1
SUSE Enterprise Storage 5:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Desktop 12 SP4:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:libvirglrenderer0-0.5.0-12.3.1

Ссылки

Описание

An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.


Затронутые продукты
HPE Helion OpenStack 8:libvirglrenderer0-0.5.0-12.3.1
SUSE Enterprise Storage 5:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Desktop 12 SP4:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:libvirglrenderer0-0.5.0-12.3.1

Ссылки

Описание

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.


Затронутые продукты
HPE Helion OpenStack 8:libvirglrenderer0-0.5.0-12.3.1
SUSE Enterprise Storage 5:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Desktop 12 SP4:libvirglrenderer0-0.5.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:libvirglrenderer0-0.5.0-12.3.1

Ссылки
Уязвимость SUSE-SU-2020:0016-1