openSUSE-SU-2021:2789-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2789-1
openSUSE-SU-2021:2789-1
Summary: Security update for qemu
Details: This update for qemu fixes the following issues: Security issues fixed: - usbredir: free call on invalid pointer in bufp_alloc (bsc#1189145, CVE-2021-3682) - NULL pointer dereference in ESP (bsc#1180433, CVE-2020-35504) (bsc#1180434, CVE-2020-35505) (bsc#1180435, CVE-2020-35506) - NULL pointer dereference issue in megasas-gen2 host bus adapter (bsc#1180432, CVE-2020-35503) - eepro100: stack overflow via infinite recursion (bsc#1182651, CVE-2021-20255) - usb: unbounded stack allocation in usbredir (bsc#1186012, CVE-2021-3527)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/, https://bugzilla.suse.com/1180432, https://bugzilla.suse.com/1180433, https://bugzilla.suse.com/1180434, https://bugzilla.suse.com/1180435, https://bugzilla.suse.com/1182651, https://bugzilla.suse.com/1186012, https://bugzilla.suse.com/1189145, https://www.suse.com/security/cve/CVE-2020-35503, https://www.suse.com/security/cve/CVE-2020-35504, https://www.suse.com/security/cve/CVE-2020-35505, https://www.suse.com/security/cve/CVE-2020-35506, https://www.suse.com/security/cve/CVE-2021-20255, https://www.suse.com/security/cve/CVE-2021-3527, https://www.suse.com/security/cve/CVE-2021-3682
Affected packages
Package
Name: qemu
Purl: pkg:rpm/opensuse/qemu&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
