SUSE-SU-2021:14774-1

    Dashboard / Vulnerabilities / SUSE-SU-2021:14774-1

    SUSE-SU-2021:14774-1

    Published: 6 Aug 2021Last Modified: 4 Feb 2026

    Summary: Security update for kvm

    Details: This update for kvm fixes the following issues: - CVE-2021-3594: invalid pointer initialization may lead to information disclosure in slirp (udp) (bsc#1187367) - CVE-2021-3592: invalid pointer initialization may lead to information disclosure (bootp). (bsc#1187364) - CVE-2021-3416: infinite loop in loopback mode may lead to stack overflow. (bsc#1186473) - CVE-2020-15469: MMIO ops null pointer dereference may lead to DoS. (bsc#1173612) - CVE-2020-11947: iscsi_aio_ioctl_cb in block/iscsi.c has a heap-based buffer over-read. (bsc#1180523) - CVE-2021-20221: out-of-bound heap buffer access via an interrupt ID field. (bsc#1181933) - CVE-2020-25707: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c. (bsc#1178683) - CVE-2020-15863: stack-based overflow in xgmac_enet_send() in hw/net/xgmac.c. (bsc#1174386)

    Affected packages

    Package

    Name: kvm

    Purl: pkg:rpm/suse/kvm&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.2-53.41.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2021:14774-1 | CVE-DB