SUSE-SU-2018:2679-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2679-1
SUSE-SU-2018:2679-1
Summary: Security update for qemu
Details: This update for qemu fixes the following issues: This security issue was fixed: - CVE-2018-12617: qmp_guest_file_read had an integer overflow that could have been exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket causing DoS (bsc#1098735) These non-security issues were fixed: - Allow kvm group access to /dev/sev (bsc#1102604). - Fix for the value used for reduced_phys_bits. Please update the reduced_phys_bits value used on the commandline or in libvirt XML to the value 1 (explicitly set now in QEMU code). (bsc#1103628) - Fix (again) the qemu guest agent udev rule file, which got unfixed in a series of unfortunate events (bsc#1094898 and now bsc#1105279)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182679-1/, https://bugzilla.suse.com/1094898, https://bugzilla.suse.com/1098735, https://bugzilla.suse.com/1102604, https://bugzilla.suse.com/1103628, https://bugzilla.suse.com/1105279, https://www.suse.com/security/cve/CVE-2018-12617
Affected packages
Package
Name: qemu
Purl: pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
