Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3744-1

Опубликовано: 22 окт. 2024
Источник: suse-cvrf

Описание

Security update for qemu

This update for qemu fixes the following issues:

Security fixes:

  • CVE-2024-8354: Fixed assertion failure in usb_ep_get() (bsc#1230834)
  • CVE-2024-8612: Fixed information leak in virtio devices (bsc#1230915)

Update version to 8.2.7:

Security fixes:

  • CVE-2024-7409: Fixed denial of service via improper synchronization in QEMU NBD Server during socket closure (bsc#1229007)
  • CVE-2024-4693: Fixed improper release of configure vector in virtio-pci that lead to guest triggerable crash (bsc#1224132)

Other fixes:

  • added missing fix for ppc64 emulation that caused corruption in userspace (bsc#1230140)
  • target/ppc: Fix lxvx/stxvx facility check (bsc#1229929)
  • accel/kvm: check for KVM_CAP_READONLY_MEM on VM (bsc#1231519)

Full changelog here:

https://lore.kernel.org/qemu-devel/d9ff276f-f1ba-4e90-8343-a7a0dc2bf305@tls.msk.ru/

Список пакетов

SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6
qemu-8.2.7-15061.6.coco15sp6.1
qemu-SLOF-8.2.7-15061.6.coco15sp6.1
qemu-accel-tcg-x86-8.2.7-15061.6.coco15sp6.1
qemu-audio-alsa-8.2.7-15061.6.coco15sp6.1
qemu-audio-dbus-8.2.7-15061.6.coco15sp6.1
qemu-audio-pa-8.2.7-15061.6.coco15sp6.1
qemu-audio-pipewire-8.2.7-15061.6.coco15sp6.1
qemu-audio-spice-8.2.7-15061.6.coco15sp6.1
qemu-block-curl-8.2.7-15061.6.coco15sp6.1
qemu-block-iscsi-8.2.7-15061.6.coco15sp6.1
qemu-block-nfs-8.2.7-15061.6.coco15sp6.1
qemu-block-rbd-8.2.7-15061.6.coco15sp6.1
qemu-block-ssh-8.2.7-15061.6.coco15sp6.1
qemu-chardev-baum-8.2.7-15061.6.coco15sp6.1
qemu-chardev-spice-8.2.7-15061.6.coco15sp6.1
qemu-guest-agent-8.2.7-15061.6.coco15sp6.1
qemu-headless-8.2.7-15061.6.coco15sp6.1
qemu-hw-display-qxl-8.2.7-15061.6.coco15sp6.1
qemu-hw-display-virtio-gpu-8.2.7-15061.6.coco15sp6.1
qemu-hw-display-virtio-gpu-pci-8.2.7-15061.6.coco15sp6.1
qemu-hw-display-virtio-vga-8.2.7-15061.6.coco15sp6.1
qemu-hw-usb-host-8.2.7-15061.6.coco15sp6.1
qemu-hw-usb-redirect-8.2.7-15061.6.coco15sp6.1
qemu-img-8.2.7-15061.6.coco15sp6.1
qemu-ipxe-8.2.7-15061.6.coco15sp6.1
qemu-ksm-8.2.7-15061.6.coco15sp6.1
qemu-lang-8.2.7-15061.6.coco15sp6.1
qemu-pr-helper-8.2.7-15061.6.coco15sp6.1
qemu-seabios-8.2.71.16.3_3_ga95067eb-15061.6.coco15sp6.1
qemu-skiboot-8.2.7-15061.6.coco15sp6.1
qemu-spice-8.2.7-15061.6.coco15sp6.1
qemu-tools-8.2.7-15061.6.coco15sp6.1
qemu-ui-curses-8.2.7-15061.6.coco15sp6.1
qemu-ui-dbus-8.2.7-15061.6.coco15sp6.1
qemu-ui-gtk-8.2.7-15061.6.coco15sp6.1
qemu-ui-opengl-8.2.7-15061.6.coco15sp6.1
qemu-ui-spice-app-8.2.7-15061.6.coco15sp6.1
qemu-ui-spice-core-8.2.7-15061.6.coco15sp6.1
qemu-vgabios-8.2.71.16.3_3_ga95067eb-15061.6.coco15sp6.1
qemu-x86-8.2.7-15061.6.coco15sp6.1

Описание

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.


Затронутые продукты
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-SLOF-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-accel-tcg-x86-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-audio-alsa-8.2.7-15061.6.coco15sp6.1

Ссылки

Описание

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.


Затронутые продукты
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-SLOF-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-accel-tcg-x86-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-audio-alsa-8.2.7-15061.6.coco15sp6.1

Ссылки

Описание

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.


Затронутые продукты
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-SLOF-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-accel-tcg-x86-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-audio-alsa-8.2.7-15061.6.coco15sp6.1

Ссылки

Описание

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.


Затронутые продукты
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-SLOF-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-accel-tcg-x86-8.2.7-15061.6.coco15sp6.1
SUSE Linux Enterprise Module for Confidential Computing Technical Preview 15 SP6:qemu-audio-alsa-8.2.7-15061.6.coco15sp6.1

Ссылки
Уязвимость SUSE-SU-2024:3744-1