Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1538-1

Опубликовано: 04 июн. 2020
Источник: suse-cvrf

Описание

Security update for qemu

This update for qemu fixes the following issues:

Security issues fixed:

  • CVE-2020-1711: Fixed a potential OOB access in the iSCSI client code (bsc#1166240).
  • CVE-2019-12068: Fixed a potential DoS in the LSI SCSI controller emulation (bsc#1146873).
  • CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940).
  • CVE-2020-8608: Fixed a potential OOB access in slirp (bsc#1163018).
  • CVE-2020-7039: Fixed a potential OOB access in slirp (bsc#1161066).
  • CVE-2019-15890: Fixed a use-after-free during packet reassembly in slirp (bsc#1149811).
  • Fixed multiple potential DoS issues in SLIRP, similar to CVE-2019-6778 (bsc#1123156).

Non-security issue fixed:

  • Make sure that required memory is mapped properly during an incoming migration of a Xen HVM domU (bsc#1160024).

Список пакетов

HPE Helion OpenStack 8
qemu-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE Enterprise Storage 5
qemu-2.9.1-6.44.1
qemu-arm-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE Linux Enterprise Server 12 SP3-BCL
qemu-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE Linux Enterprise Server 12 SP3-LTSS
qemu-2.9.1-6.44.1
qemu-arm-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-ppc-2.9.1-6.44.1
qemu-s390-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
qemu-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-ppc-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE OpenStack Cloud 8
qemu-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1
SUSE OpenStack Cloud Crowbar 8
qemu-2.9.1-6.44.1
qemu-block-curl-2.9.1-6.44.1
qemu-block-iscsi-2.9.1-6.44.1
qemu-block-rbd-2.9.1-6.44.1
qemu-block-ssh-2.9.1-6.44.1
qemu-guest-agent-2.9.1-6.44.1
qemu-ipxe-1.0.0+-6.44.1
qemu-kvm-2.9.1-6.44.1
qemu-lang-2.9.1-6.44.1
qemu-seabios-1.10.2-6.44.1
qemu-sgabios-8-6.44.1
qemu-tools-2.9.1-6.44.1
qemu-vgabios-1.10.2-6.44.1
qemu-x86-2.9.1-6.44.1

Описание

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки

Описание

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.


Затронутые продукты
HPE Helion OpenStack 8:qemu-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.44.1
HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.44.1

Ссылки
Уязвимость SUSE-SU-2020:1538-1