QID 750149
QID 750149: SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2021:1942-1)
This update for qemu fixes the following issues: - switch method of splitting off hw-s390x-virtio-gpu-ccw.so as a module to what was accepted upstream (bsc#1181103) - fix oob access in sdhci interface (cve-2020-17380, bsc#1175144, cve-2020-25085, bsc#1176681, cve-2021-3409, bsc#1182282) - fix potential privilege escalation in virtiofsd tool (cve-2021-20263, bsc#1183373) - fix oob access (stack overflow) in rtl8139 nic emulation (cve-2021-3416, bsc#1182968) - fix heap overflow in msix emulation (cve-2020-27821, bsc#1179686) - fix package scripts to not use hard coded paths for temporary working directories and log files (bsc#1182425) - qemu bios fails to read stage2 loader on s390x (bsc#1186290) - for the record, these issues are fixed in this package already.
Most are alternate references to previously mentioned issues: (cve-2019-15890, bsc#1149813, cve-2020-8608, bsc#1163019, cve-2020-14364, bsc#1175534, cve-2020-25707, bsc#1178683, cve-2020-25723, bsc#1178935, cve-2020-29130, bsc#1179477, cve-2020-29129, bsc#1179484, cve-2021-3419, bsc#1182975)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation allows attacker to compromise the system.
- SUSE-SU-2021:1942-1 -
lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html
CVEs related to QID 750149
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SUSE-SU-2021:1942-1 | SUSE Enterprise Linux |
|