Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2983-1

Опубликовано: 20 авг. 2024
Источник: suse-cvrf

Описание

Security update for qemu

This update for qemu fixes the following issues:

  • CVE-2024-4467: Fixed denial of service and file read/write via qemu-img info command (bsc#1227322)

  • CVE-2024-7409: Fixed denial of service via improper synchronization in QEMU NBD Server during socket closure (bsc#1229007)

    • nbd/server: Close stray clients at server-stop
    • nbd/server: Drop non-negotiating clients
    • nbd/server: Cap default max-connections to 100
    • nbd/server: Plumb in new args to nbd_client_add()
    • nbd: Minor style and typo fixes
  • Update qemu to version 8.2.6

Список пакетов

Container bci/kiwi:latest
qemu-img-8.2.6-150600.3.9.1
qemu-pr-helper-8.2.6-150600.3.9.1
qemu-tools-8.2.6-150600.3.9.1
Image SLES15-SP6-EC2-ECS-HVM
qemu-img-8.2.6-150600.3.9.1
qemu-pr-helper-8.2.6-150600.3.9.1
qemu-tools-8.2.6-150600.3.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
qemu-img-8.2.6-150600.3.9.1
qemu-pr-helper-8.2.6-150600.3.9.1
qemu-tools-8.2.6-150600.3.9.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
qemu-SLOF-8.2.6-150600.3.9.1
qemu-accel-qtest-8.2.6-150600.3.9.1
qemu-accel-tcg-x86-8.2.6-150600.3.9.1
qemu-arm-8.2.6-150600.3.9.1
qemu-audio-alsa-8.2.6-150600.3.9.1
qemu-audio-jack-8.2.6-150600.3.9.1
qemu-audio-oss-8.2.6-150600.3.9.1
qemu-audio-pa-8.2.6-150600.3.9.1
qemu-audio-spice-8.2.6-150600.3.9.1
qemu-block-dmg-8.2.6-150600.3.9.1
qemu-block-gluster-8.2.6-150600.3.9.1
qemu-block-nfs-8.2.6-150600.3.9.1
qemu-chardev-spice-8.2.6-150600.3.9.1
qemu-extra-8.2.6-150600.3.9.1
qemu-hw-display-qxl-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-pci-8.2.6-150600.3.9.1
qemu-hw-display-virtio-vga-8.2.6-150600.3.9.1
qemu-hw-s390x-virtio-gpu-ccw-8.2.6-150600.3.9.1
qemu-hw-usb-redirect-8.2.6-150600.3.9.1
qemu-hw-usb-smartcard-8.2.6-150600.3.9.1
qemu-ivshmem-tools-8.2.6-150600.3.9.1
qemu-linux-user-8.2.6-150600.3.9.1
qemu-microvm-8.2.6-150600.3.9.1
qemu-ppc-8.2.6-150600.3.9.1
qemu-s390x-8.2.6-150600.3.9.1
qemu-seabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-skiboot-8.2.6-150600.3.9.1
qemu-ui-gtk-8.2.6-150600.3.9.1
qemu-ui-opengl-8.2.6-150600.3.9.1
qemu-ui-spice-app-8.2.6-150600.3.9.1
qemu-ui-spice-core-8.2.6-150600.3.9.1
qemu-vgabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-vhost-user-gpu-8.2.6-150600.3.9.1
qemu-x86-8.2.6-150600.3.9.1
SUSE Linux Enterprise Module for Server Applications 15 SP6
qemu-8.2.6-150600.3.9.1
qemu-SLOF-8.2.6-150600.3.9.1
qemu-accel-tcg-x86-8.2.6-150600.3.9.1
qemu-arm-8.2.6-150600.3.9.1
qemu-audio-alsa-8.2.6-150600.3.9.1
qemu-audio-dbus-8.2.6-150600.3.9.1
qemu-audio-pa-8.2.6-150600.3.9.1
qemu-audio-pipewire-8.2.6-150600.3.9.1
qemu-audio-spice-8.2.6-150600.3.9.1
qemu-block-curl-8.2.6-150600.3.9.1
qemu-block-iscsi-8.2.6-150600.3.9.1
qemu-block-nfs-8.2.6-150600.3.9.1
qemu-block-rbd-8.2.6-150600.3.9.1
qemu-block-ssh-8.2.6-150600.3.9.1
qemu-chardev-baum-8.2.6-150600.3.9.1
qemu-chardev-spice-8.2.6-150600.3.9.1
qemu-guest-agent-8.2.6-150600.3.9.1
qemu-headless-8.2.6-150600.3.9.1
qemu-hw-display-qxl-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-pci-8.2.6-150600.3.9.1
qemu-hw-display-virtio-vga-8.2.6-150600.3.9.1
qemu-hw-s390x-virtio-gpu-ccw-8.2.6-150600.3.9.1
qemu-hw-usb-host-8.2.6-150600.3.9.1
qemu-hw-usb-redirect-8.2.6-150600.3.9.1
qemu-ipxe-8.2.6-150600.3.9.1
qemu-ksm-8.2.6-150600.3.9.1
qemu-lang-8.2.6-150600.3.9.1
qemu-ppc-8.2.6-150600.3.9.1
qemu-s390x-8.2.6-150600.3.9.1
qemu-seabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-skiboot-8.2.6-150600.3.9.1
qemu-spice-8.2.6-150600.3.9.1
qemu-ui-curses-8.2.6-150600.3.9.1
qemu-ui-dbus-8.2.6-150600.3.9.1
qemu-ui-gtk-8.2.6-150600.3.9.1
qemu-ui-opengl-8.2.6-150600.3.9.1
qemu-ui-spice-app-8.2.6-150600.3.9.1
qemu-ui-spice-core-8.2.6-150600.3.9.1
qemu-vgabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-x86-8.2.6-150600.3.9.1
openSUSE Leap 15.6
qemu-8.2.6-150600.3.9.1
qemu-SLOF-8.2.6-150600.3.9.1
qemu-accel-qtest-8.2.6-150600.3.9.1
qemu-accel-tcg-x86-8.2.6-150600.3.9.1
qemu-arm-8.2.6-150600.3.9.1
qemu-audio-alsa-8.2.6-150600.3.9.1
qemu-audio-dbus-8.2.6-150600.3.9.1
qemu-audio-jack-8.2.6-150600.3.9.1
qemu-audio-pa-8.2.6-150600.3.9.1
qemu-audio-pipewire-8.2.6-150600.3.9.1
qemu-audio-spice-8.2.6-150600.3.9.1
qemu-block-curl-8.2.6-150600.3.9.1
qemu-block-dmg-8.2.6-150600.3.9.1
qemu-block-gluster-8.2.6-150600.3.9.1
qemu-block-iscsi-8.2.6-150600.3.9.1
qemu-block-nfs-8.2.6-150600.3.9.1
qemu-block-rbd-8.2.6-150600.3.9.1
qemu-block-ssh-8.2.6-150600.3.9.1
qemu-chardev-baum-8.2.6-150600.3.9.1
qemu-chardev-spice-8.2.6-150600.3.9.1
qemu-doc-8.2.6-150600.3.9.1
qemu-extra-8.2.6-150600.3.9.1
qemu-guest-agent-8.2.6-150600.3.9.1
qemu-headless-8.2.6-150600.3.9.1
qemu-hw-display-qxl-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-8.2.6-150600.3.9.1
qemu-hw-display-virtio-gpu-pci-8.2.6-150600.3.9.1
qemu-hw-display-virtio-vga-8.2.6-150600.3.9.1
qemu-hw-s390x-virtio-gpu-ccw-8.2.6-150600.3.9.1
qemu-hw-usb-host-8.2.6-150600.3.9.1
qemu-hw-usb-redirect-8.2.6-150600.3.9.1
qemu-hw-usb-smartcard-8.2.6-150600.3.9.1
qemu-img-8.2.6-150600.3.9.1
qemu-ipxe-8.2.6-150600.3.9.1
qemu-ivshmem-tools-8.2.6-150600.3.9.1
qemu-ksm-8.2.6-150600.3.9.1
qemu-lang-8.2.6-150600.3.9.1
qemu-linux-user-8.2.6-150600.3.9.1
qemu-microvm-8.2.6-150600.3.9.1
qemu-ppc-8.2.6-150600.3.9.1
qemu-pr-helper-8.2.6-150600.3.9.1
qemu-s390x-8.2.6-150600.3.9.1
qemu-seabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-skiboot-8.2.6-150600.3.9.1
qemu-spice-8.2.6-150600.3.9.1
qemu-tools-8.2.6-150600.3.9.1
qemu-ui-curses-8.2.6-150600.3.9.1
qemu-ui-dbus-8.2.6-150600.3.9.1
qemu-ui-gtk-8.2.6-150600.3.9.1
qemu-ui-opengl-8.2.6-150600.3.9.1
qemu-ui-spice-app-8.2.6-150600.3.9.1
qemu-ui-spice-core-8.2.6-150600.3.9.1
qemu-vgabios-8.2.61.16.3_3_ga95067eb-150600.3.9.1
qemu-vhost-user-gpu-8.2.6-150600.3.9.1
qemu-x86-8.2.6-150600.3.9.1

Описание

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.


Затронутые продукты
Container bci/kiwi:latest:qemu-img-8.2.6-150600.3.9.1
Container bci/kiwi:latest:qemu-pr-helper-8.2.6-150600.3.9.1
Container bci/kiwi:latest:qemu-tools-8.2.6-150600.3.9.1
Image SLES15-SP6-EC2-ECS-HVM:qemu-img-8.2.6-150600.3.9.1

Ссылки

Описание

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.


Затронутые продукты
Container bci/kiwi:latest:qemu-img-8.2.6-150600.3.9.1
Container bci/kiwi:latest:qemu-pr-helper-8.2.6-150600.3.9.1
Container bci/kiwi:latest:qemu-tools-8.2.6-150600.3.9.1
Image SLES15-SP6-EC2-ECS-HVM:qemu-img-8.2.6-150600.3.9.1

Ссылки