FlawAtlas
Search the atlas
SUSE-SU-2019:2157-1 Not scored

Security update for qemu

This update for qemu fixes the following issues: Security issues fixed: - CVE-2019-14378: Security fix for heap overflow in ip_reass on big packet input (bsc#1143794). - CVE-2019-12155: Security fix for null pointer dereference while releasing spice resources (bsc#1135902). - CVE-2019-13164: Security fix for qemu-bridge-helper ACL can be bypassed when names are too long (bsc#1140402).

Exploit probability Not scored
Published September 6, 2019
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 4 qemu
SUSE:Linux Enterprise Server 12 SP2-BCL qemu
SUSE:Linux Enterprise Server 12 SP2-LTSS qemu
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 qemu
SUSE:OpenStack Cloud 7 qemu

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:2157-1

This update for qemu fixes the following issues: Security issues fixed: - CVE-2019-14378: Security fix for heap overflow in ip_reass on big packet input (bsc#1143794). - CVE-2019-12155: Security fix for null pointer dereference while releasing spice resources (bsc#1135902). - CVE-2019-13164: Security fix for qemu-bridge-helper ACL can be bypassed when names are too long (bsc#1140402).

View original source

05 / REFERENCES

Further evidence