SUSE-SU-2016:0459-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0459-1
SUSE-SU-2016:0459-1
Summary: Security update for qemu
Details: This update fixes the following security issues: - Enforce receive packet size, thus eliminating buffer overflow and potential security issue. (bsc#957162 CVE-2015-7512) - Infinite loop in processing command block list. CVE-2015-8345 (bsc#956829): This update also fixes a non-security bug: - Due to space restrictions in limited bios data areas, don't create mptable if vcpu count is 'high' (ie more than ~19). (bsc#954864) (No supported guests are negatively impacted by this change, which is taken from upstream seabios)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160459-1/, https://bugzilla.suse.com/954864, https://bugzilla.suse.com/956829, https://bugzilla.suse.com/957162, https://www.suse.com/security/cve/CVE-2015-7512, https://www.suse.com/security/cve/CVE-2015-8345
Affected packages
Package
Name: qemu
Purl: pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
