Upstream information

CVE-2016-1714 at MITRE

Description

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.89
Vector AV:L/AC:M/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
CVSS v3 Scores
  National Vulnerability Database
Base Score 8.1
Vector AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Access Vector Local
Access Complexity High
Privileges Required None
User Interaction None
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
SUSE Bugzilla entries: 961691 [RESOLVED / FIXED], 961692 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP4
  • xen >= 4.4.4_02-32.1
  • xen-doc-html >= 4.4.4_02-32.1
  • xen-kmp-default >= 4.4.4_02_3.0.101_68-32.1
  • xen-kmp-pae >= 4.4.4_02_3.0.101_68-32.1
  • xen-libs >= 4.4.4_02-32.1
  • xen-libs-32bit >= 4.4.4_02-32.1
  • xen-tools >= 4.4.4_02-32.1
  • xen-tools-domU >= 4.4.4_02-32.1
Patchnames:
sledsp4-xen-12492
SUSE Linux Enterprise Desktop 12
  • qemu >= 2.0.2-48.19.1
  • qemu-block-curl >= 2.0.2-48.19.1
  • qemu-ipxe >= 1.0.0-48.19.1
  • qemu-kvm >= 2.0.2-48.19.1
  • qemu-seabios >= 1.7.4-48.19.1
  • qemu-sgabios >= 8-48.19.1
  • qemu-tools >= 2.0.2-48.19.1
  • qemu-vgabios >= 1.7.4-48.19.1
  • qemu-x86 >= 2.0.2-48.19.1
  • xen >= 4.4.4_02-22.19.1
  • xen-kmp-default >= 4.4.4_02_k3.12.55_52.42-22.19.1
  • xen-libs >= 4.4.4_02-22.19.1
  • xen-libs-32bit >= 4.4.4_02-22.19.1
Patchnames:
SUSE-SLE-DESKTOP-12-2016-779
SUSE-SLE-DESKTOP-12-2016-924
SUSE Linux Enterprise Desktop 12 SP1
  • qemu >= 2.3.1-14.1
  • qemu-block-curl >= 2.3.1-14.1
  • qemu-ipxe >= 1.0.0-14.1
  • qemu-kvm >= 2.3.1-14.1
  • qemu-seabios >= 1.8.1-14.1
  • qemu-sgabios >= 8-14.1
  • qemu-tools >= 2.3.1-14.1
  • qemu-vgabios >= 1.8.1-14.1
  • qemu-x86 >= 2.3.1-14.1
  • xen >= 4.5.2_06-7.1
  • xen-kmp-default >= 4.5.2_06_k3.12.53_60.30-7.1
  • xen-libs >= 4.5.2_06-7.1
  • xen-libs-32bit >= 4.5.2_06-7.1
Patchnames:
SUSE-SLE-DESKTOP-12-SP1-2016-1007
SUSE-SLE-DESKTOP-12-SP1-2016-508
SUSE Linux Enterprise Desktop 12 SP2
  • qemu >= 2.6.1-27.15
  • qemu-block-curl >= 2.6.1-27.15
  • qemu-ipxe >= 1.0.0-27.15
  • qemu-kvm >= 2.6.1-27.15
  • qemu-seabios >= 1.9.1-27.15
  • qemu-sgabios >= 8-27.15
  • qemu-tools >= 2.6.1-27.15
  • qemu-vgabios >= 1.9.1-27.15
  • qemu-x86 >= 2.6.1-27.15
  • xen >= 4.7.0_12-23.4
  • xen-libs >= 4.7.0_12-23.4
  • xen-libs-32bit >= 4.7.0_12-23.4
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA qemu
SUSE Linux Enterprise Desktop 12 SP2 GA xen
SUSE Linux Enterprise Server 11 SP2-LTSS
  • xen >= 4.1.6_08-26.1
  • xen-devel >= 4.1.6_08-26.1
  • xen-doc-html >= 4.1.6_08-26.1
  • xen-doc-pdf >= 4.1.6_08-26.1
  • xen-kmp-default >= 4.1.6_08_3.0.101_0.7.37-26.1
  • xen-kmp-pae >= 4.1.6_08_3.0.101_0.7.37-26.1
  • xen-kmp-trace >= 4.1.6_08_3.0.101_0.7.37-26.1
  • xen-libs >= 4.1.6_08-26.1
  • xen-libs-32bit >= 4.1.6_08-26.1
  • xen-tools >= 4.1.6_08-26.1
  • xen-tools-domU >= 4.1.6_08-26.1
Patchnames:
slessp2-xen-12530
SUSE Linux Enterprise Server 11 SP3-LTSS
  • kvm >= 1.4.2-46.1
  • xen >= 4.2.5_20-24.9
  • xen-doc-html >= 4.2.5_20-24.9
  • xen-doc-pdf >= 4.2.5_20-24.9
  • xen-kmp-default >= 4.2.5_20_3.0.101_0.47.79-24.9
  • xen-kmp-pae >= 4.2.5_20_3.0.101_0.47.79-24.9
  • xen-libs >= 4.2.5_20-24.9
  • xen-libs-32bit >= 4.2.5_20-24.9
  • xen-tools >= 4.2.5_20-24.9
  • xen-tools-domU >= 4.2.5_20-24.9
Patchnames:
slessp3-kvm-12634
slessp3-xen-12639
SUSE Linux Enterprise Server 11 SP4
  • kvm >= 1.4.2-44.1
  • xen >= 4.4.4_02-32.1
  • xen-doc-html >= 4.4.4_02-32.1
  • xen-kmp-default >= 4.4.4_02_3.0.101_68-32.1
  • xen-kmp-pae >= 4.4.4_02_3.0.101_68-32.1
  • xen-libs >= 4.4.4_02-32.1
  • xen-libs-32bit >= 4.4.4_02-32.1
  • xen-tools >= 4.4.4_02-32.1
  • xen-tools-domU >= 4.4.4_02-32.1
Patchnames:
slessp4-kvm-12645
slessp4-xen-12492
SUSE Linux Enterprise Server 12
  • qemu >= 2.0.2-48.19.1
  • qemu-block-curl >= 2.0.2-48.19.1
  • qemu-block-rbd >= 2.0.2-48.19.1
  • qemu-guest-agent >= 2.0.2-48.19.1
  • qemu-ipxe >= 1.0.0-48.19.1
  • qemu-kvm >= 2.0.2-48.19.1
  • qemu-lang >= 2.0.2-48.19.1
  • qemu-ppc >= 2.0.2-48.19.1
  • qemu-s390 >= 2.0.2-48.19.1
  • qemu-seabios >= 1.7.4-48.19.1
  • qemu-sgabios >= 8-48.19.1
  • qemu-tools >= 2.0.2-48.19.1
  • qemu-vgabios >= 1.7.4-48.19.1
  • qemu-x86 >= 2.0.2-48.19.1
  • xen >= 4.4.4_02-22.19.1
  • xen-doc-html >= 4.4.4_02-22.19.1
  • xen-kmp-default >= 4.4.4_02_k3.12.55_52.42-22.19.1
  • xen-libs >= 4.4.4_02-22.19.1
  • xen-libs-32bit >= 4.4.4_02-22.19.1
  • xen-tools >= 4.4.4_02-22.19.1
  • xen-tools-domU >= 4.4.4_02-22.19.1
Patchnames:
SUSE-SLE-SERVER-12-2016-779
SUSE-SLE-SERVER-12-2016-924
SUSE Linux Enterprise Server 12 SP1
  • qemu >= 2.3.1-14.1
  • qemu-block-curl >= 2.3.1-14.1
  • qemu-block-rbd >= 2.3.1-14.1
  • qemu-guest-agent >= 2.3.1-14.1
  • qemu-ipxe >= 1.0.0-14.1
  • qemu-kvm >= 2.3.1-14.1
  • qemu-lang >= 2.3.1-14.1
  • qemu-ppc >= 2.3.1-14.1
  • qemu-s390 >= 2.3.1-14.1
  • qemu-seabios >= 1.8.1-14.1
  • qemu-sgabios >= 8-14.1
  • qemu-tools >= 2.3.1-14.1
  • qemu-vgabios >= 1.8.1-14.1
  • qemu-x86 >= 2.3.1-14.1
  • xen >= 4.5.2_06-7.1
  • xen-doc-html >= 4.5.2_06-7.1
  • xen-kmp-default >= 4.5.2_06_k3.12.53_60.30-7.1
  • xen-libs >= 4.5.2_06-7.1
  • xen-libs-32bit >= 4.5.2_06-7.1
  • xen-tools >= 4.5.2_06-7.1
  • xen-tools-domU >= 4.5.2_06-7.1
Patchnames:
SUSE-SLE-SERVER-12-SP1-2016-1007
SUSE-SLE-SERVER-12-SP1-2016-508
SUSE Linux Enterprise Server 12 SP2
  • qemu >= 2.6.1-27.15
  • qemu-arm >= 2.6.1-27.15
  • qemu-block-curl >= 2.6.1-27.15
  • qemu-block-rbd >= 2.6.1-27.15
  • qemu-block-ssh >= 2.6.1-27.15
  • qemu-guest-agent >= 2.6.1-27.15
  • qemu-ipxe >= 1.0.0-27.15
  • qemu-kvm >= 2.6.1-27.15
  • qemu-lang >= 2.6.1-27.15
  • qemu-ppc >= 2.6.1-27.15
  • qemu-s390 >= 2.6.1-27.15
  • qemu-seabios >= 1.9.1-27.15
  • qemu-sgabios >= 8-27.15
  • qemu-tools >= 2.6.1-27.15
  • qemu-vgabios >= 1.9.1-27.15
  • qemu-x86 >= 2.6.1-27.15
  • xen >= 4.7.0_12-23.4
  • xen-doc-html >= 4.7.0_12-23.4
  • xen-libs >= 4.7.0_12-23.4
  • xen-libs-32bit >= 4.7.0_12-23.4
  • xen-tools >= 4.7.0_12-23.4
  • xen-tools-domU >= 4.7.0_12-23.4
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA qemu
SUSE Linux Enterprise Server 12 SP2 GA xen
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • qemu >= 2.6.1-27.15
  • qemu-arm >= 2.6.1-27.15
  • qemu-block-curl >= 2.6.1-27.15
  • qemu-block-rbd >= 2.6.1-27.15
  • qemu-block-ssh >= 2.6.1-27.15
  • qemu-guest-agent >= 2.6.1-27.15
  • qemu-ipxe >= 1.0.0-27.15
  • qemu-lang >= 2.6.1-27.15
  • qemu-tools >= 2.6.1-27.15
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA qemu
SUSE Linux Enterprise Software Development Kit 11 SP4
  • xen >= 4.4.4_02-32.1
  • xen-devel >= 4.4.4_02-32.1
Patchnames:
sdksp4-xen-12492
SUSE Linux Enterprise Software Development Kit 12
  • xen >= 4.4.4_02-22.19.1
  • xen-devel >= 4.4.4_02-22.19.1
Patchnames:
SUSE-SLE-SDK-12-2016-779
SUSE Linux Enterprise Software Development Kit 12 SP1
  • xen >= 4.5.2_06-7.1
  • xen-devel >= 4.5.2_06-7.1
Patchnames:
SUSE-SLE-SDK-12-SP1-2016-508
SUSE Linux Enterprise Software Development Kit 12 SP2
  • xen-devel >= 4.7.0_12-23.4
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA xen-devel
openSUSE 13.2
  • xen >= 4.4.4_02-43.1
  • xen-debugsource >= 4.4.4_02-43.1
  • xen-devel >= 4.4.4_02-43.1
  • xen-doc-html >= 4.4.4_02-43.1
  • xen-kmp-default >= 4.4.4_02_k3.16.7_35-43.1
  • xen-kmp-default-debuginfo >= 4.4.4_02_k3.16.7_35-43.1
  • xen-kmp-desktop >= 4.4.4_02_k3.16.7_35-43.1
  • xen-kmp-desktop-debuginfo >= 4.4.4_02_k3.16.7_35-43.1
  • xen-libs >= 4.4.4_02-43.1
  • xen-libs-32bit >= 4.4.4_02-43.1
  • xen-libs-debuginfo >= 4.4.4_02-43.1
  • xen-libs-debuginfo-32bit >= 4.4.4_02-43.1
  • xen-tools >= 4.4.4_02-43.1
  • xen-tools-debuginfo >= 4.4.4_02-43.1
  • xen-tools-domU >= 4.4.4_02-43.1
  • xen-tools-domU-debuginfo >= 4.4.4_02-43.1
Patchnames:
openSUSE-2016-439
openSUSE Leap 42.1
  • qemu >= 2.3.1-15.1
  • qemu-arm >= 2.3.1-15.1
  • qemu-arm-debuginfo >= 2.3.1-15.1
  • qemu-block-curl >= 2.3.1-15.1
  • qemu-block-curl-debuginfo >= 2.3.1-15.1
  • qemu-block-rbd >= 2.3.1-15.1
  • qemu-block-rbd-debuginfo >= 2.3.1-15.1
  • qemu-debugsource >= 2.3.1-15.1
  • qemu-extra >= 2.3.1-15.1
  • qemu-extra-debuginfo >= 2.3.1-15.1
  • qemu-guest-agent >= 2.3.1-15.1
  • qemu-guest-agent-debuginfo >= 2.3.1-15.1
  • qemu-ipxe >= 1.0.0-15.1
  • qemu-kvm >= 2.3.1-15.1
  • qemu-lang >= 2.3.1-15.1
  • qemu-linux-user >= 2.3.1-15.1
  • qemu-linux-user-debuginfo >= 2.3.1-15.1
  • qemu-linux-user-debugsource >= 2.3.1-15.1
  • qemu-ppc >= 2.3.1-15.1
  • qemu-ppc-debuginfo >= 2.3.1-15.1
  • qemu-s390 >= 2.3.1-15.1
  • qemu-s390-debuginfo >= 2.3.1-15.1
  • qemu-seabios >= 1.8.1-15.1
  • qemu-sgabios >= 8-15.1
  • qemu-testsuite >= 2.3.1-15.2
  • qemu-tools >= 2.3.1-15.1
  • qemu-tools-debuginfo >= 2.3.1-15.1
  • qemu-vgabios >= 1.8.1-15.1
  • qemu-x86 >= 2.3.1-15.1
  • qemu-x86-debuginfo >= 2.3.1-15.1
  • xen >= 4.5.3_10-15.2
  • xen-debugsource >= 4.5.3_10-15.2
  • xen-devel >= 4.5.3_10-15.2
  • xen-doc-html >= 4.5.3_10-15.2
  • xen-kmp-default >= 4.5.3_10_k4.1.31_30-15.2
  • xen-kmp-default-debuginfo >= 4.5.3_10_k4.1.31_30-15.2
  • xen-libs >= 4.5.3_10-15.2
  • xen-libs-32bit >= 4.5.3_10-15.2
  • xen-libs-debuginfo >= 4.5.3_10-15.2
  • xen-libs-debuginfo-32bit >= 4.5.3_10-15.2
  • xen-tools >= 4.5.3_10-15.2
  • xen-tools-debuginfo >= 4.5.3_10-15.2
  • xen-tools-domU >= 4.5.3_10-15.2
  • xen-tools-domU-debuginfo >= 4.5.3_10-15.2
Patchnames:
openSUSE-2016-1170
openSUSE-2016-413
openSUSE-2016-839
openSUSE Leap 42.2
  • qemu >= 2.6.1-21.1
  • qemu-arm >= 2.6.1-21.1
  • qemu-block-curl >= 2.6.1-21.1
  • qemu-block-dmg >= 2.6.1-21.1
  • qemu-block-iscsi >= 2.6.1-21.1
  • qemu-block-rbd >= 2.6.1-21.1
  • qemu-block-ssh >= 2.6.1-21.1
  • qemu-extra >= 2.6.1-21.1
  • qemu-ipxe >= 1.0.0-21.1
  • qemu-kvm >= 2.6.1-21.1
  • qemu-lang >= 2.6.1-21.1
  • qemu-linux-user >= 2.6.1-21.1
  • qemu-ppc >= 2.6.1-21.1
  • qemu-s390 >= 2.6.1-21.1
  • qemu-seabios >= 1.9.1-21.1
  • qemu-sgabios >= 8-21.1
  • qemu-tools >= 2.6.1-21.1
  • qemu-vgabios >= 1.9.1-21.1
  • qemu-x86 >= 2.6.1-21.1
  • xen >= 4.7.0_12-1.6
  • xen-doc-html >= 4.7.0_12-1.6
  • xen-libs >= 4.7.0_12-1.6
  • xen-tools >= 4.7.0_12-1.6
  • xen-tools-domU >= 4.7.0_12-1.6
Patchnames:
openSUSE Leap 42.2 GA qemu
openSUSE Leap 42.2 GA qemu-linux-user
openSUSE Leap 42.2 GA xen
openSUSE Tumbleweed
  • xen >= 4.7.0_12-1.3
  • xen-devel >= 4.7.0_12-1.3
  • xen-doc-html >= 4.7.0_12-1.3
  • xen-libs >= 4.7.0_12-1.3
  • xen-libs-32bit >= 4.7.0_12-1.3
  • xen-tools >= 4.7.0_12-1.3
  • xen-tools-domU >= 4.7.0_12-1.3
Patchnames:
openSUSE Tumbleweed GA xen