Security update for qemu
This update fixes the following security issues: - Enforce receive packet size, thus eliminating buffer overflow and potential security issue. (bsc#957162 CVE-2015-7512) - Infinite loop in processing command block list. CVE-2015-8345 (bsc#956829): Also a non-security bug fixed: - Fix cases of wrong clock values in kvmclock timekeeping (bsc#947164 and bsc#953187)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following security issues: - Enforce receive packet size, thus eliminating buffer overflow and potential security issue. (bsc#957162 CVE-2015-7512) - Infinite loop in processing command block list. CVE-2015-8345 (bsc#956829): Also a non-security bug fixed: - Fix cases of wrong clock values in kvmclock timekeeping (bsc#947164 and bsc#953187)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/947164
- https://bugzilla.suse.com/953187
- https://bugzilla.suse.com/956829
- https://bugzilla.suse.com/957162
- https://www.suse.com/security/cve/CVE-2015-7512
- https://www.suse.com/security/cve/CVE-2015-8345
- https://www.suse.com/support/update/announcement/2016/suse-su-20160021-1/