FlawAtlas
Search the atlas
SUSE-SU-2020:1538-1 Not scored

Security update for qemu

This update for qemu fixes the following issues: Security issues fixed: - CVE-2020-1711: Fixed a potential OOB access in the iSCSI client code (bsc#1166240). - CVE-2019-12068: Fixed a potential DoS in the LSI SCSI controller emulation (bsc#1146873). - CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940). - CVE-2020-8608: Fixed a potential OOB access in slirp (bsc#1163018). - CVE-2020-7039: Fixed a potential OOB access in slirp (bsc#1161066). - CVE-2019-15890: Fixed a use-after-free during packet reassembly in slirp (bsc#1149811). - Fixed multiple potential DoS issues in SLIRP, similar to CVE-2019-6778 (bsc#1123156). Non-security issue fixed: - Make sure that required memory is mapped properly during an incoming migration of a Xen HVM domU (bsc#1160024).

Exploit probability Not scored
Published June 4, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 5 qemu
SUSE:HPE Helion OpenStack 8 qemu
SUSE:Linux Enterprise Server 12 SP3-BCL qemu
SUSE:Linux Enterprise Server 12 SP3-LTSS qemu
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 qemu
SUSE:OpenStack Cloud 8 qemu
SUSE:OpenStack Cloud Crowbar 8 qemu

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:1538-1

This update for qemu fixes the following issues: Security issues fixed: - CVE-2020-1711: Fixed a potential OOB access in the iSCSI client code (bsc#1166240). - CVE-2019-12068: Fixed a potential DoS in the LSI SCSI controller emulation (bsc#1146873). - CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940). - CVE-2020-8608: Fixed a potential OOB access in slirp (bsc#1163018). - CVE-2020-7039: Fixed a potential OOB access in slirp (bsc#1161066). - CVE-2019-15890: Fixed a use-after-free during packet reassembly in slirp (bsc#1149811). - Fixed multiple potential DoS issues in SLIRP, similar to CVE-2019-6778 (bsc#1123156). Non-security issue fixed: - Make sure that required memory is mapped properly during an incoming migration of a Xen HVM domU (bsc#1160024).

View original source

05 / REFERENCES

Further evidence