Описание
Security update for qemu
This update for qemu fixes the following issues:
- CVE-2021-20196: Fixed a denial of service in the floppy disk emulator (bsc#1181361).
- CVE-2021-3930: Fixed a potential denial of service in the emulated SCSI device (bsc#1192525).
Non-security fixes:
- Fixed a kernel data corruption via a long kernel boot cmdline (bsc#1196737).
Список пакетов
Image SLES12-SP5-EC2-ECS-On-Demand
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
Ссылки
- Link for SUSE-SU-2022:1151-1
- E-Mail link for SUSE-SU-2022:1151-1
- SUSE Security Ratings
- SUSE Bug 1181361
- SUSE Bug 1187529
- SUSE Bug 1192463
- SUSE Bug 1192525
- SUSE Bug 1196737
- SUSE CVE CVE-2021-20196 page
- SUSE CVE CVE-2021-3930 page
Описание
A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Затронутые продукты
Ссылки
- CVE-2021-20196
- SUSE Bug 1181361
Описание
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Затронутые продукты
Ссылки
- CVE-2021-3930
- SUSE Bug 1192525
- SUSE Bug 1192526