{"schema_version":"1.7.3","id":"SUSE-SU-2018:0019-1","published":"2018-01-04T12:57:52Z","modified":"2026-02-04T02:36:51.128514Z","related":["CVE-2017-2633","CVE-2017-5715"],"upstream":["CVE-2017-2633","CVE-2017-5715"],"summary":"Security update for kvm","details":"\n\nThis update for kvm fixes the following issues:\n\nAlso a mitigation for a security flaw has been applied:\n\n- CVE-2017-5715: QEMU was updated to allow passing through new MSR and CPUID flags from \n  the host VM to the CPU, to allow enabling/disabling branch prediction features in the\n  Intel CPU. (bsc#1068032)\n\nSecurity fixes have been applied:\n\n- CVE-2017-2633: Fix various out of bounds access issues in the QEMU vnc infrastructure (bsc#1026612)\n","affected":[{"package":{"name":"kvm","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/kvm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.2-60.6.1"}]}],"ecosystem_specific":{"binaries":[{"kvm":"1.4.2-60.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0019-1.json"}},{"package":{"name":"kvm","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/kvm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.2-60.6.1"}]}],"ecosystem_specific":{"binaries":[{"kvm":"1.4.2-60.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0019-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180019-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1026612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1068032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2633"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5715"}]}