Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1526-1

Опубликовано: 03 июн. 2020
Источник: suse-cvrf

Описание

Security update for qemu

This update for qemu fixes the following issues:

Security issues fixed:

  • CVE-2020-1711: Fixed a potential OOB access in the iSCSI client code (bsc#1166240).
  • CVE-2019-12068: Fixed a potential DoS in the LSI SCSI controller emulation (bsc#1146873).
  • CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940).
  • CVE-2020-8608: Fixed a potential OOB access in slirp (bsc#1163018).
  • CVE-2020-7039: Fixed a potential OOB access in slirp (bsc#1161066).
  • CVE-2019-15890: Fixed a use-after-free during packet reassembly in slirp (bsc#1149811).
  • Fixed multiple potential DoS issues in SLIRP, similar to CVE-2019-6778 (bsc#1123156).

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
qemu-2.6.2-41.59.1
qemu-block-curl-2.6.2-41.59.1
qemu-block-rbd-2.6.2-41.59.1
qemu-block-ssh-2.6.2-41.59.1
qemu-guest-agent-2.6.2-41.59.1
qemu-ipxe-1.0.0-41.59.1
qemu-kvm-2.6.2-41.59.1
qemu-lang-2.6.2-41.59.1
qemu-seabios-1.9.1-41.59.1
qemu-sgabios-8-41.59.1
qemu-tools-2.6.2-41.59.1
qemu-vgabios-1.9.1-41.59.1
qemu-x86-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-LTSS
qemu-2.6.2-41.59.1
qemu-block-curl-2.6.2-41.59.1
qemu-block-rbd-2.6.2-41.59.1
qemu-block-ssh-2.6.2-41.59.1
qemu-guest-agent-2.6.2-41.59.1
qemu-ipxe-1.0.0-41.59.1
qemu-kvm-2.6.2-41.59.1
qemu-lang-2.6.2-41.59.1
qemu-ppc-2.6.2-41.59.1
qemu-s390-2.6.2-41.59.1
qemu-seabios-1.9.1-41.59.1
qemu-sgabios-8-41.59.1
qemu-tools-2.6.2-41.59.1
qemu-vgabios-1.9.1-41.59.1
qemu-x86-2.6.2-41.59.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
qemu-2.6.2-41.59.1
qemu-block-curl-2.6.2-41.59.1
qemu-block-rbd-2.6.2-41.59.1
qemu-block-ssh-2.6.2-41.59.1
qemu-guest-agent-2.6.2-41.59.1
qemu-ipxe-1.0.0-41.59.1
qemu-kvm-2.6.2-41.59.1
qemu-lang-2.6.2-41.59.1
qemu-ppc-2.6.2-41.59.1
qemu-seabios-1.9.1-41.59.1
qemu-sgabios-8-41.59.1
qemu-tools-2.6.2-41.59.1
qemu-vgabios-1.9.1-41.59.1
qemu-x86-2.6.2-41.59.1
SUSE OpenStack Cloud 7
qemu-2.6.2-41.59.1
qemu-block-curl-2.6.2-41.59.1
qemu-block-rbd-2.6.2-41.59.1
qemu-block-ssh-2.6.2-41.59.1
qemu-guest-agent-2.6.2-41.59.1
qemu-ipxe-1.0.0-41.59.1
qemu-kvm-2.6.2-41.59.1
qemu-lang-2.6.2-41.59.1
qemu-s390-2.6.2-41.59.1
qemu-seabios-1.9.1-41.59.1
qemu-sgabios-8-41.59.1
qemu-tools-2.6.2-41.59.1
qemu-vgabios-1.9.1-41.59.1
qemu-x86-2.6.2-41.59.1

Описание

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки

Описание

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-curl-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-rbd-2.6.2-41.59.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-block-ssh-2.6.2-41.59.1

Ссылки
Уязвимость SUSE-SU-2020:1526-1