Multiple vulnerabilities in QEMU
This document (7016590) is provided subject to the disclaimer at the end of this document.
Environment
SUSE Linux Enterprise Server 11 Service Pack 3 (SLES 11 SP3)
SUSE Linux Enterprise Server 11 Service Pack 2 (SLES 11 SP2 LTSS)
Situation
The highest vulnerability rating of these issues is major and allows privilege escalation from guest to host for certain configurations.
Vulnerabilities of Xen on SLE 12 and SLE 11 SP3
- CVE-2015-4103 / XSA-128 / bsc#931625: Denial of Service (previously published)
- CVE-2015-4104 / XSA-129 / bsc#931626: Denial of Service (previously published)
- CVE-2015-4105 / XSA-130 / bsc#931627: Denial of Service (previously published)
- CVE-2015-4106 / XSA-131 / bsc#931628: Denial of Service, Privilege Escalation, Information Disclosure (previously published)
- CVE-2015-4163 / XSA-134 / bsc#932790: Denial of Service (published 2015-06-11)
- CVE-2015-3209 / XSA-135 / bsc#932770: Privilege Escalation from guest to host (published 2015-06-10)
- CVE-2015-4164 / XSA-136 / bsc#932996: Denial of Service (published 2015-06-11)
Updated packages are available for SLES 11 SP3 x86_64 (64 bit), SLES 11 SP3 x86 (32 bit), SLES 12.
Vulnerabilities of QEMU (KVM) on SLES 12
- CVE-2015-3209 / XSA-135 / bsc#932770: Privilege Escalation from guest to host (published 2015-06-10)
- CVE-2015-4037 / bsc#932267: Denial of Service (previously published)
Status of the updated packages: in QA, awaiting release.
Vulnerabilities of KVM (QEMU) on SLES 11 SP3
- CVE-2015-3209 / XSA-135 / bsc#932770: Privilege Escalation from guest to host (published 2015-06-10)
- CVE-2015-4037 / bsc#932267: Denial of Service (previously published)
Updated packages are available for SLES 11 SP3 x86_64 (64 bit), SLES 11 SP3 x86 (32 bit)
Note
The Xen Security Advisories and SUSE Bugzilla information will be unlocked upon public announcement. Most details from http://xenbits.xen.org/xsa/ will be included in the bugzilla entries.
Resolution
Cause
Additional Information
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7016590
- Creation Date: 09-Jun-2015
- Modified Date:03-Mar-2020
-
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com