Описание
Security update for qemu
This update for qemu fixes the following issues:
- CVE-2022-4144: Fixed qxl_phys2virt unsafe address translation that can lead to out-of-bounds read (bsc#1205808).
- CVE-2022-3165: Fixed integer underflow in vnc_client_cut_text_ext() (bsc#1203788).
- CVE-2022-1050: Fixed use-after-free issue in pvrdma_exec_cmd() (bsc#1197653).
Bugfixes:
- Fixed deviation of guest clock (bsc#1206527).
- Fixed broken 'block limits' VPD emulation (bsc#1202364).
Список пакетов
Container suse/sle-micro-rancher/5.3:latest
Container suse/sle-micro-rancher/5.4:latest
Image SLES15-SP4-EC2-ECS-HVM
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Module for Server Applications 15 SP4
openSUSE Leap 15.4
openSUSE Leap Micro 5.3
Ссылки
- Link for SUSE-SU-2023:0671-1
- E-Mail link for SUSE-SU-2023:0671-1
- SUSE Security Ratings
- SUSE Bug 1197653
- SUSE Bug 1202364
- SUSE Bug 1203788
- SUSE Bug 1205808
- SUSE Bug 1206527
- SUSE CVE CVE-2022-1050 page
- SUSE CVE CVE-2022-3165 page
- SUSE CVE CVE-2022-4144 page
Описание
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
Затронутые продукты
Ссылки
- CVE-2022-1050
- SUSE Bug 1197653
Описание
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
Затронутые продукты
Ссылки
- CVE-2022-3165
- SUSE Bug 1203788
Описание
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.
Затронутые продукты
Ссылки
- CVE-2022-4144
- SUSE Bug 1205808