SUSE SLES12 Security Update : qemu (SUSE-SU-2016:2781-1)

This script is Copyright (C) 2016 Tenable Network Security, Inc.


Synopsis :

The remote SUSE host is missing one or more security updates.

Description :

qemu was updated to fix 21 security issues. These security issues were
fixed :

- CVE-2014-5388: Off-by-one error in the pci_read function
in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in
QEMU allowed local guest users to obtain sensitive
information and have other unspecified impact related to
a crafted PCI device that triggers memory corruption
(bsc#893323).

- CVE-2015-6815: e1000 NIC emulation support was
vulnerable to an infinite loop issue. A privileged user
inside guest could have used this flaw to crash the Qemu
instance resulting in DoS. (bsc#944697).

- CVE-2016-2391: The ohci_bus_start function in the USB
OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU
allowed local guest OS administrators to cause a denial
of service (NULL pointer dereference and QEMU process
crash) via vectors related to multiple eof_timers
(bsc#967013).

- CVE-2016-2392: The is_rndis function in the USB Net
device emulator (hw/usb/dev-network.c) in QEMU did not
properly validate USB configuration descriptor objects,
which allowed local guest OS administrators to cause a
denial of service (NULL pointer dereference and QEMU
process crash) via vectors involving a remote NDIS
control message packet (bsc#967012).

- CVE-2016-4453: The vmsvga_fifo_run function in
hw/display/vmware_vga.c in QEMU allowed local guest OS
administrators to cause a denial of service (infinite
loop and QEMU process crash) via a VGA command
(bsc#982223).

- CVE-2016-4454: The vmsvga_fifo_read_raw function in
hw/display/vmware_vga.c in QEMU allowed local guest OS
administrators to obtain sensitive host memory
information or cause a denial of service (QEMU process
crash) by changing FIFO registers and issuing a VGA
command, which triggers an out-of-bounds read
(bsc#982222).

- CVE-2016-5105: The megasas_dcmd_cfg_read function in
hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS
8708EM2 Host Bus Adapter emulation support, used an
uninitialized variable, which allowed local guest
administrators to read host memory via vectors involving
a MegaRAID Firmware Interface (MFI) command
(bsc#982017).

- CVE-2016-5106: The megasas_dcmd_set_properties function
in hw/scsi/megasas.c in QEMU, when built with MegaRAID
SAS 8708EM2 Host Bus Adapter emulation support, allowed
local guest administrators to cause a denial of service
(out-of-bounds write access) via vectors involving a
MegaRAID Firmware Interface (MFI) command (bsc#982018).

- CVE-2016-5107: The megasas_lookup_frame function in
QEMU, when built with MegaRAID SAS 8708EM2 Host Bus
Adapter emulation support, allowed local guest OS
administrators to cause a denial of service
(out-of-bounds read and crash) via unspecified vectors
(bsc#982019).

- CVE-2016-5126: Heap-based buffer overflow in the
iscsi_aio_ioctl function in block/iscsi.c in QEMU
allowed local guest OS users to cause a denial of
service (QEMU process crash) or possibly execute
arbitrary code via a crafted iSCSI asynchronous I/O
ioctl call (bsc#982285).

- CVE-2016-5238: The get_cmd function in hw/scsi/esp.c in
QEMU allowed local guest OS administrators to cause a
denial of service (out-of-bounds write and QEMU process
crash) via vectors related to reading from the
information transfer buffer in non-DMA mode
(bsc#982959).

- CVE-2016-5337: The megasas_ctrl_get_info function in
hw/scsi/megasas.c in QEMU allowed local guest OS
administrators to obtain sensitive host memory
information via vectors related to reading device
control information (bsc#983961).

- CVE-2016-5338: The (1) esp_reg_read and (2)
esp_reg_write functions in hw/scsi/esp.c in QEMU allowed
local guest OS administrators to cause a denial of
service (QEMU process crash) or execute arbitrary code
on the QEMU host via vectors related to the information
transfer buffer (bsc#983982).

- CVE-2016-5403: The virtqueue_pop function in
hw/virtio/virtio.c in QEMU allowed local guest OS
administrators to cause a denial of service (memory
consumption and QEMU process crash) by submitting
requests without waiting for completion (bsc#991080).

- CVE-2016-6490: Infinite loop in the virtio framework. A
privileged user inside the guest could have used this
flaw to crash the Qemu instance on the host resulting in
DoS (bsc#991466).

- CVE-2016-6833: Use-after-free issue in the VMWARE
VMXNET3 NIC device support. A privileged user inside
guest could have used this issue to crash the Qemu
instance resulting in DoS (bsc#994774).

- CVE-2016-6836: VMWARE VMXNET3 NIC device support was
leaging information leakage. A privileged user inside
guest could have used this to leak host memory bytes to
a guest (bsc#994760).

- CVE-2016-6888: Integer overflow in packet initialisation
in VMXNET3 device driver. A privileged user inside guest
could have used this flaw to crash the Qemu instance
resulting in DoS (bsc#994771).

- CVE-2016-7116: Host directory sharing via Plan 9 File
System(9pfs) was vulnerable to a directory/path
traversal issue. A privileged user inside guest could
have used this flaw to access undue files on the host
(bsc#996441).

- CVE-2016-7155: In the VMWARE PVSCSI paravirtual SCSI bus
a OOB access and/or infinite loop issue could have
allowed a privileged user inside guest to crash the Qemu
process resulting in DoS (bsc#997858).

- CVE-2016-7156: In the VMWARE PVSCSI paravirtual SCSI bus
a infinite loop issue could have allowed a privileged
user inside guest to crash the Qemu process resulting in
DoS (bsc#997859).

Note that Tenable Network Security has extracted the preceding
description block directly from the SUSE security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.suse.com/893323
https://bugzilla.suse.com/944697
https://bugzilla.suse.com/967012
https://bugzilla.suse.com/967013
https://bugzilla.suse.com/982017
https://bugzilla.suse.com/982018
https://bugzilla.suse.com/982019
https://bugzilla.suse.com/982222
https://bugzilla.suse.com/982223
https://bugzilla.suse.com/982285
https://bugzilla.suse.com/982959
https://bugzilla.suse.com/983961
https://bugzilla.suse.com/983982
https://bugzilla.suse.com/991080
https://bugzilla.suse.com/991466
https://bugzilla.suse.com/994760
https://bugzilla.suse.com/994771
https://bugzilla.suse.com/994774
https://bugzilla.suse.com/996441
https://bugzilla.suse.com/997858
https://bugzilla.suse.com/997859
https://www.suse.com/security/cve/CVE-2014-5388.html
https://www.suse.com/security/cve/CVE-2015-6815.html
https://www.suse.com/security/cve/CVE-2016-2391.html
https://www.suse.com/security/cve/CVE-2016-2392.html
https://www.suse.com/security/cve/CVE-2016-4453.html
https://www.suse.com/security/cve/CVE-2016-4454.html
https://www.suse.com/security/cve/CVE-2016-5105.html
https://www.suse.com/security/cve/CVE-2016-5106.html
https://www.suse.com/security/cve/CVE-2016-5107.html
https://www.suse.com/security/cve/CVE-2016-5126.html
https://www.suse.com/security/cve/CVE-2016-5238.html
https://www.suse.com/security/cve/CVE-2016-5337.html
https://www.suse.com/security/cve/CVE-2016-5338.html
https://www.suse.com/security/cve/CVE-2016-5403.html
https://www.suse.com/security/cve/CVE-2016-6490.html
https://www.suse.com/security/cve/CVE-2016-6833.html
https://www.suse.com/security/cve/CVE-2016-6836.html
https://www.suse.com/security/cve/CVE-2016-6888.html
https://www.suse.com/security/cve/CVE-2016-7116.html
https://www.suse.com/security/cve/CVE-2016-7155.html
https://www.suse.com/security/cve/CVE-2016-7156.html
http://www.nessus.org/u?c217bbcd

Solution :

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product :

SUSE Linux Enterprise Server for SAP 12:zypper in -t patch
SUSE-SLE-SAP-12-2016-1646=1

SUSE Linux Enterprise Server 12-LTSS:zypper in -t patch
SUSE-SLE-SERVER-12-2016-1646=1

To bring your system up-to-date, use 'zypper patch'.

Risk factor :

Medium / CVSS Base Score : 4.9
(CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 4.0
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true