SUSE update for qemu



Published: 2024-09-02
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-4467
CWE-ID CWE-400
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
openSUSE Leap Micro
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

Server Applications Module
Operating systems & Components / Operating system

SUSE Package Hub 15
Operating systems & Components / Operating system

Basesystem Module
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

qemu-block-rbd-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-rbd
Operating systems & Components / Operating system package or component

qemu-vgabios
Operating systems & Components / Operating system package or component

qemu-microvm
Operating systems & Components / Operating system package or component

qemu-SLOF
Operating systems & Components / Operating system package or component

qemu-ipxe
Operating systems & Components / Operating system package or component

qemu-skiboot
Operating systems & Components / Operating system package or component

qemu-seabios
Operating systems & Components / Operating system package or component

qemu-sgabios
Operating systems & Components / Operating system package or component

qemu-kvm
Operating systems & Components / Operating system package or component

qemu-linux-user-debugsource
Operating systems & Components / Operating system package or component

qemu-hw-s390x-virtio-gpu-ccw-debuginfo
Operating systems & Components / Operating system package or component

qemu-arm-debuginfo
Operating systems & Components / Operating system package or component

qemu-accel-qtest-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-opengl-debuginfo
Operating systems & Components / Operating system package or component

qemu-vhost-user-gpu
Operating systems & Components / Operating system package or component

qemu-chardev-spice
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-gpu-pci-debuginfo
Operating systems & Components / Operating system package or component

qemu-tools
Operating systems & Components / Operating system package or component

qemu-audio-oss
Operating systems & Components / Operating system package or component

qemu-ppc
Operating systems & Components / Operating system package or component

qemu-hw-usb-host-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-gluster
Operating systems & Components / Operating system package or component

qemu-block-curl-debuginfo
Operating systems & Components / Operating system package or component

qemu-ppc-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-iscsi
Operating systems & Components / Operating system package or component

qemu-audio-alsa
Operating systems & Components / Operating system package or component

qemu-vhost-user-gpu-debuginfo
Operating systems & Components / Operating system package or component

qemu-x86-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-dbus
Operating systems & Components / Operating system package or component

qemu-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-usb-redirect
Operating systems & Components / Operating system package or component

qemu-block-nfs
Operating systems & Components / Operating system package or component

qemu-block-gluster-debuginfo
Operating systems & Components / Operating system package or component

qemu-ivshmem-tools-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-dmg
Operating systems & Components / Operating system package or component

qemu-hw-s390x-virtio-gpu-ccw
Operating systems & Components / Operating system package or component

qemu-debugsource
Operating systems & Components / Operating system package or component

qemu-hw-usb-smartcard-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-alsa-debuginfo
Operating systems & Components / Operating system package or component

qemu-guest-agent
Operating systems & Components / Operating system package or component

qemu-guest-agent-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-gpu-pci
Operating systems & Components / Operating system package or component

qemu-lang
Operating systems & Components / Operating system package or component

qemu-hw-display-qxl-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-spice-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-spice
Operating systems & Components / Operating system package or component

qemu-linux-user-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-pa
Operating systems & Components / Operating system package or component

qemu-hw-usb-smartcard
Operating systems & Components / Operating system package or component

qemu-x86
Operating systems & Components / Operating system package or component

qemu-s390x-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-dmg-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-usb-redirect-debuginfo
Operating systems & Components / Operating system package or component

qemu-chardev-baum-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-gpu-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-spice-core-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-curses
Operating systems & Components / Operating system package or component

qemu-chardev-baum
Operating systems & Components / Operating system package or component

qemu-extra-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-curl
Operating systems & Components / Operating system package or component

qemu-ui-dbus-debuginfo
Operating systems & Components / Operating system package or component

qemu-audio-dbus-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-spice-app
Operating systems & Components / Operating system package or component

qemu-ui-dbus
Operating systems & Components / Operating system package or component

qemu-ui-gtk
Operating systems & Components / Operating system package or component

qemu-audio-pa-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-iscsi-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-nfs-debuginfo
Operating systems & Components / Operating system package or component

qemu-linux-user
Operating systems & Components / Operating system package or component

qemu-ksm
Operating systems & Components / Operating system package or component

qemu-headless
Operating systems & Components / Operating system package or component

qemu
Operating systems & Components / Operating system package or component

qemu-ui-spice-core
Operating systems & Components / Operating system package or component

qemu-ivshmem-tools
Operating systems & Components / Operating system package or component

qemu-s390x
Operating systems & Components / Operating system package or component

qemu-tools-debuginfo
Operating systems & Components / Operating system package or component

qemu-block-ssh
Operating systems & Components / Operating system package or component

qemu-accel-tcg-x86-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-curses-debuginfo
Operating systems & Components / Operating system package or component

qemu-accel-tcg-x86
Operating systems & Components / Operating system package or component

qemu-audio-oss-debuginfo
Operating systems & Components / Operating system package or component

qemu-arm
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-vga
Operating systems & Components / Operating system package or component

qemu-extra
Operating systems & Components / Operating system package or component

qemu-audio-jack
Operating systems & Components / Operating system package or component

qemu-chardev-spice-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-gtk-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-vga-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-spice-app-debuginfo
Operating systems & Components / Operating system package or component

qemu-hw-display-qxl
Operating systems & Components / Operating system package or component

qemu-accel-qtest
Operating systems & Components / Operating system package or component

qemu-hw-display-virtio-gpu
Operating systems & Components / Operating system package or component

qemu-audio-jack-debuginfo
Operating systems & Components / Operating system package or component

qemu-ui-opengl
Operating systems & Components / Operating system package or component

qemu-hw-usb-host
Operating systems & Components / Operating system package or component

qemu-block-ssh-debuginfo
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource exhaustion

EUVDB-ID: #VU94526

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-4467

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the qemu-img utility when handling a specially crafted image file containing a "json:{}" value. A remote attacker can trick the victim into loading a specially crafted image file and perform a denial of service (DoS) attack.

Mitigation

Update the affected package qemu to the latest version.

Vulnerable software versions

openSUSE Leap Micro: 5.5

SUSE Linux Enterprise Micro: 5.5

Server Applications Module: 15-SP5

SUSE Package Hub 15: 15-SP5

Basesystem Module: 15-SP5

SUSE Linux Enterprise Server for SAP Applications 15: SP5

SUSE Linux Enterprise Server 15: SP5

SUSE Linux Enterprise Real Time 15: SP5

SUSE Linux Enterprise High Performance Computing 15: SP5

SUSE Linux Enterprise Desktop 15: SP5

openSUSE Leap: 15.5

qemu-block-rbd-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-rbd: before 7.1.0-150500.49.18.1

qemu-vgabios: before 1.16.0_0_gd239552-150500.49.18.1

qemu-microvm: before 7.1.0-150500.49.18.1

qemu-SLOF: before 7.1.0-150500.49.18.1

qemu-ipxe: before 1.0.0+-150500.49.18.1

qemu-skiboot: before 7.1.0-150500.49.18.1

qemu-seabios: before 1.16.0_0_gd239552-150500.49.18.1

qemu-sgabios: before 8-150500.49.18.1

qemu-kvm: before 7.1.0-150500.49.18.1

qemu-linux-user-debugsource: before 7.1.0-150500.49.18.1

qemu-hw-s390x-virtio-gpu-ccw-debuginfo: before 7.1.0-150500.49.18.1

qemu-arm-debuginfo: before 7.1.0-150500.49.18.1

qemu-accel-qtest-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-opengl-debuginfo: before 7.1.0-150500.49.18.1

qemu-vhost-user-gpu: before 7.1.0-150500.49.18.1

qemu-chardev-spice: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-gpu-pci-debuginfo: before 7.1.0-150500.49.18.1

qemu-tools: before 7.1.0-150500.49.18.1

qemu-audio-oss: before 7.1.0-150500.49.18.1

qemu-ppc: before 7.1.0-150500.49.18.1

qemu-hw-usb-host-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-gluster: before 7.1.0-150500.49.18.1

qemu-block-curl-debuginfo: before 7.1.0-150500.49.18.1

qemu-ppc-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-iscsi: before 7.1.0-150500.49.18.1

qemu-audio-alsa: before 7.1.0-150500.49.18.1

qemu-vhost-user-gpu-debuginfo: before 7.1.0-150500.49.18.1

qemu-x86-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-dbus: before 7.1.0-150500.49.18.1

qemu-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-usb-redirect: before 7.1.0-150500.49.18.1

qemu-block-nfs: before 7.1.0-150500.49.18.1

qemu-block-gluster-debuginfo: before 7.1.0-150500.49.18.1

qemu-ivshmem-tools-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-dmg: before 7.1.0-150500.49.18.1

qemu-hw-s390x-virtio-gpu-ccw: before 7.1.0-150500.49.18.1

qemu-debugsource: before 7.1.0-150500.49.18.1

qemu-hw-usb-smartcard-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-alsa-debuginfo: before 7.1.0-150500.49.18.1

qemu-guest-agent: before 7.1.0-150500.49.18.1

qemu-guest-agent-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-gpu-pci: before 7.1.0-150500.49.18.1

qemu-lang: before 7.1.0-150500.49.18.1

qemu-hw-display-qxl-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-spice-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-spice: before 7.1.0-150500.49.18.1

qemu-linux-user-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-pa: before 7.1.0-150500.49.18.1

qemu-hw-usb-smartcard: before 7.1.0-150500.49.18.1

qemu-x86: before 7.1.0-150500.49.18.1

qemu-s390x-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-dmg-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-usb-redirect-debuginfo: before 7.1.0-150500.49.18.1

qemu-chardev-baum-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-gpu-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-spice-core-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-curses: before 7.1.0-150500.49.18.1

qemu-chardev-baum: before 7.1.0-150500.49.18.1

qemu-extra-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-curl: before 7.1.0-150500.49.18.1

qemu-ui-dbus-debuginfo: before 7.1.0-150500.49.18.1

qemu-audio-dbus-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-spice-app: before 7.1.0-150500.49.18.1

qemu-ui-dbus: before 7.1.0-150500.49.18.1

qemu-ui-gtk: before 7.1.0-150500.49.18.1

qemu-audio-pa-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-iscsi-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-nfs-debuginfo: before 7.1.0-150500.49.18.1

qemu-linux-user: before 7.1.0-150500.49.18.1

qemu-ksm: before 7.1.0-150500.49.18.1

qemu-headless: before 7.1.0-150500.49.18.1

qemu: before 7.1.0-150500.49.18.1

qemu-ui-spice-core: before 7.1.0-150500.49.18.1

qemu-ivshmem-tools: before 7.1.0-150500.49.18.1

qemu-s390x: before 7.1.0-150500.49.18.1

qemu-tools-debuginfo: before 7.1.0-150500.49.18.1

qemu-block-ssh: before 7.1.0-150500.49.18.1

qemu-accel-tcg-x86-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-curses-debuginfo: before 7.1.0-150500.49.18.1

qemu-accel-tcg-x86: before 7.1.0-150500.49.18.1

qemu-audio-oss-debuginfo: before 7.1.0-150500.49.18.1

qemu-arm: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-vga: before 7.1.0-150500.49.18.1

qemu-extra: before 7.1.0-150500.49.18.1

qemu-audio-jack: before 7.1.0-150500.49.18.1

qemu-chardev-spice-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-gtk-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-vga-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-spice-app-debuginfo: before 7.1.0-150500.49.18.1

qemu-hw-display-qxl: before 7.1.0-150500.49.18.1

qemu-accel-qtest: before 7.1.0-150500.49.18.1

qemu-hw-display-virtio-gpu: before 7.1.0-150500.49.18.1

qemu-audio-jack-debuginfo: before 7.1.0-150500.49.18.1

qemu-ui-opengl: before 7.1.0-150500.49.18.1

qemu-hw-usb-host: before 7.1.0-150500.49.18.1

qemu-block-ssh-debuginfo: before 7.1.0-150500.49.18.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243077-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###