Описание
Security update for qemu
This update for qemu fixes the following issues:
-
CVE-2024-4467: Fixed denial of service and file read/write via qemu-img info command (bsc#1227322)
-
CVE-2024-7409: Fixed denial of service via improper synchronization in QEMU NBD Server during socket closure (bsc#1229007)
- nbd/server: Close stray clients at server-stop
- nbd/server: Drop non-negotiating clients
- nbd/server: Cap default max-connections to 100
- nbd/server: Plumb in new args to nbd_client_add()
- nbd: Minor style and typo fixes
-
Update qemu to version 8.2.6
Список пакетов
Container bci/kiwi:latest
Image SLES15-SP6-EC2-ECS-HVM
SUSE Linux Enterprise Module for Basesystem 15 SP6
SUSE Linux Enterprise Module for Package Hub 15 SP6
SUSE Linux Enterprise Module for Server Applications 15 SP6
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2024:2983-1
- E-Mail link for SUSE-SU-2024:2983-1
- SUSE Security Ratings
- SUSE Bug 1227322
- SUSE Bug 1229007
- SUSE CVE CVE-2024-4467 page
- SUSE CVE CVE-2024-7409 page
Описание
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.
Затронутые продукты
Ссылки
- CVE-2024-4467
- SUSE Bug 1227322
Описание
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
Затронутые продукты
Ссылки
- CVE-2024-7409
- SUSE Bug 1229007