Описание
Security update for qemu
This update for qemu fixes the following issues:
- CVE-2023-3301: Fixed incorrect cleanup of the vdpa/vhost-net structures if peer nic is present (bsc#1213414).
- CVE-2023-0330: Fixed reentrancy issues in the LSI controller (bsc#1207205).
- CVE-2023-2861: Fixed opening special files in 9pfs (bsc#1212968).
- CVE-2023-3255: Fixed infinite loop in inflate_buffer() leads to denial of service (bsc#1213001).
Bugfixes:
- hw/ide/piix: properly initialize the BMIBA register (bsc#bsc#1179993)
- Fixed issue where Guest did not run on XEN SLES15SP2 (bsc#1181740).
Список пакетов
Container suse/sle-micro/kvm-5.5:latest
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Server Applications 15 SP5
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2023:3082-1
- E-Mail link for SUSE-SU-2023:3082-1
- SUSE Security Ratings
- SUSE Bug 1179993
- SUSE Bug 1181740
- SUSE Bug 1207205
- SUSE Bug 1212968
- SUSE Bug 1213001
- SUSE Bug 1213414
- SUSE CVE CVE-2023-0330 page
- SUSE CVE CVE-2023-2861 page
- SUSE CVE CVE-2023-3255 page
- SUSE CVE CVE-2023-3301 page
Описание
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
Затронутые продукты
Ссылки
- CVE-2023-0330
- SUSE Bug 1207205
Описание
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
Затронутые продукты
Ссылки
- CVE-2023-2861
- SUSE Bug 1212968
Описание
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.
Затронутые продукты
Ссылки
- CVE-2023-3255
- SUSE Bug 1213001
Описание
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2023-3301
- SUSE Bug 1213414