openSUSE Security Update : qemu (openSUSE-2016-1504)

critical Nessus Plugin ID 96129
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for qemu to version 2.6.2 fixes the several issues.

These security issues were fixed :

- CVE-2016-7161: Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allowed attackers to execute arbitrary code on the QEMU host via a large ethlite packet (bsc#1001151).

- CVE-2016-7170: OOB stack memory access when processing svga command (bsc#998516).

- CVE-2016-7466: xhci memory leakage during device unplug (bsc#1000345).

- CVE-2016-7422: NULL pointer dereference in virtqueu_map_desc (bsc#1000346).

- CVE-2016-7908: The mcf_fec_do_tx function in hw/net/mcf_fec.c did not properly limit the buffer descriptor count when transmitting packets, which allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags (bsc#1002550).

- CVE-2016-7995: Memory leak in ehci_process_itd (bsc#1003612).

- CVE-2016-8576: The xhci_ring_fetch function in hw/usb/hcd-xhci.c allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process (bsc#1003878).

- CVE-2016-8578: The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c allowed local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation (bsc#1003894).

- CVE-2016-9105: Memory leakage in v9fs_link (bsc#1007494).

- CVE-2016-8577: Memory leak in the v9fs_read function in hw/9pfs/9p.c allowed local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation (bsc#1003893).

- CVE-2016-9106: Memory leakage in v9fs_write (bsc#1007495).

- CVE-2016-8669: The serial_update_parameters function in hw/char/serial.c allowed local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base (bsc#1004707).

- CVE-2016-7909: The pcnet_rdra_addr function in hw/net/pcnet.c allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0 (bsc#1002557).

- CVE-2016-9101: eepro100 memory leakage whern unplugging a device (bsc#1007391).

- CVE-2016-8668: The rocker_io_writel function in hw/net/rocker/rocker.c allowed local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size (bsc#1004706).

- CVE-2016-8910: The rtl8139_cplus_transmit function in hw/net/rtl8139.c allowed local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count (bsc#1006538).

- CVE-2016-8909: The intel_hda_xfer function in hw/audio/intel-hda.c allowed local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position (bsc#1006536).

- CVE-2016-7994: Memory leak in virtio_gpu_resource_create_2d (bsc#1003613).

- CVE-2016-9104: Integer overflow leading to OOB access in 9pfs (bsc#1007493).

- CVE-2016-8667: The rc4030_write function in hw/dma/rc4030.c allowed local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value (bsc#1004702).

- CVE-2016-7907: The pcnet_rdra_addr function in hw/net/pcnet.c allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0 (bsc#1002549).

These non-security issues were fixed :

- Change kvm-supported.txt to be per-architecture documentation, stored in the package documentation directory of each per-arch package (bsc#1005353).

- Update support doc to include current ARM64 (AArch64) support stance (bsc#1005374).

- Fix migration failure when snapshot also has been done (bsc#1008148).

- Change package post script udevadm trigger calls to be device specific (bsc#1002116).

- Add qmp-commands.txt documentation file back in. It was inadvertently dropped.

- Add an x86 cpu option (l3-cache) to specify that an L3 cache is present and another option (cpuid-0xb) to enable the cpuid 0xb leaf (bsc#1007769).

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Solution

Update the affected qemu packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1000345

https://bugzilla.opensuse.org/show_bug.cgi?id=1000346

https://bugzilla.opensuse.org/show_bug.cgi?id=1001151

https://bugzilla.opensuse.org/show_bug.cgi?id=1002116

https://bugzilla.opensuse.org/show_bug.cgi?id=1002549

https://bugzilla.opensuse.org/show_bug.cgi?id=1002550

https://bugzilla.opensuse.org/show_bug.cgi?id=1002557

https://bugzilla.opensuse.org/show_bug.cgi?id=1003612

https://bugzilla.opensuse.org/show_bug.cgi?id=1003613

https://bugzilla.opensuse.org/show_bug.cgi?id=1003878

https://bugzilla.opensuse.org/show_bug.cgi?id=1003893

https://bugzilla.opensuse.org/show_bug.cgi?id=1003894

https://bugzilla.opensuse.org/show_bug.cgi?id=1004702

https://bugzilla.opensuse.org/show_bug.cgi?id=1004706

https://bugzilla.opensuse.org/show_bug.cgi?id=1004707

https://bugzilla.opensuse.org/show_bug.cgi?id=1005353

https://bugzilla.opensuse.org/show_bug.cgi?id=1005374

https://bugzilla.opensuse.org/show_bug.cgi?id=1006536

https://bugzilla.opensuse.org/show_bug.cgi?id=1006538

https://bugzilla.opensuse.org/show_bug.cgi?id=1007391

https://bugzilla.opensuse.org/show_bug.cgi?id=1007493

https://bugzilla.opensuse.org/show_bug.cgi?id=1007494

https://bugzilla.opensuse.org/show_bug.cgi?id=1007495

https://bugzilla.opensuse.org/show_bug.cgi?id=1007769

https://bugzilla.opensuse.org/show_bug.cgi?id=1008148

https://bugzilla.opensuse.org/show_bug.cgi?id=998516

https://features.opensuse.org/

Plugin Details

Severity: Critical

ID: 96129

File Name: openSUSE-2016-1504.nasl

Version: 3.4

Type: local

Agent: unix

Published: 12/27/2016

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:qemu, p-cpe:/a:novell:opensuse:qemu-arm, p-cpe:/a:novell:opensuse:qemu-arm-debuginfo, p-cpe:/a:novell:opensuse:qemu-block-curl, p-cpe:/a:novell:opensuse:qemu-block-curl-debuginfo, p-cpe:/a:novell:opensuse:qemu-block-dmg, p-cpe:/a:novell:opensuse:qemu-block-dmg-debuginfo, p-cpe:/a:novell:opensuse:qemu-block-iscsi, p-cpe:/a:novell:opensuse:qemu-block-iscsi-debuginfo, p-cpe:/a:novell:opensuse:qemu-block-rbd, p-cpe:/a:novell:opensuse:qemu-block-rbd-debuginfo, p-cpe:/a:novell:opensuse:qemu-block-ssh, p-cpe:/a:novell:opensuse:qemu-block-ssh-debuginfo, p-cpe:/a:novell:opensuse:qemu-debugsource, p-cpe:/a:novell:opensuse:qemu-extra, p-cpe:/a:novell:opensuse:qemu-extra-debuginfo, p-cpe:/a:novell:opensuse:qemu-guest-agent, p-cpe:/a:novell:opensuse:qemu-guest-agent-debuginfo, p-cpe:/a:novell:opensuse:qemu-ipxe, p-cpe:/a:novell:opensuse:qemu-kvm, p-cpe:/a:novell:opensuse:qemu-lang, p-cpe:/a:novell:opensuse:qemu-linux-user, p-cpe:/a:novell:opensuse:qemu-linux-user-debuginfo, p-cpe:/a:novell:opensuse:qemu-linux-user-debugsource, p-cpe:/a:novell:opensuse:qemu-ppc, p-cpe:/a:novell:opensuse:qemu-ppc-debuginfo, p-cpe:/a:novell:opensuse:qemu-s390, p-cpe:/a:novell:opensuse:qemu-s390-debuginfo, p-cpe:/a:novell:opensuse:qemu-seabios, p-cpe:/a:novell:opensuse:qemu-sgabios, p-cpe:/a:novell:opensuse:qemu-testsuite, p-cpe:/a:novell:opensuse:qemu-tools, p-cpe:/a:novell:opensuse:qemu-tools-debuginfo, p-cpe:/a:novell:opensuse:qemu-vgabios, p-cpe:/a:novell:opensuse:qemu-x86, p-cpe:/a:novell:opensuse:qemu-x86-debuginfo, cpe:/o:novell:opensuse:42.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 12/22/2016

Reference Information

CVE: CVE-2016-7161, CVE-2016-7170, CVE-2016-7422, CVE-2016-7466, CVE-2016-7907, CVE-2016-7908, CVE-2016-7909, CVE-2016-7994, CVE-2016-7995, CVE-2016-8576, CVE-2016-8577, CVE-2016-8578, CVE-2016-8667, CVE-2016-8668, CVE-2016-8669, CVE-2016-8909, CVE-2016-8910, CVE-2016-9101, CVE-2016-9104, CVE-2016-9105, CVE-2016-9106