{"affected":[{"ecosystem_specific":{"binaries":[{"kvm":"1.4.2-60.6.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"kvm","purl":"pkg:rpm/suse/kvm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.4.2-60.6.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kvm":"1.4.2-60.6.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"kvm","purl":"pkg:rpm/suse/kvm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.4.2-60.6.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n\nThis update for kvm fixes the following issues:\n\nAlso a mitigation for a security flaw has been applied:\n\n- CVE-2017-5715: QEMU was updated to allow passing through new MSR and CPUID flags from \n  the host VM to the CPU, to allow enabling/disabling branch prediction features in the\n  Intel CPU. (bsc#1068032)\n\nSecurity fixes have been applied:\n\n- CVE-2017-2633: Fix various out of bounds access issues in the QEMU vnc infrastructure (bsc#1026612)\n","id":"SUSE-SU-2018:0019-1","modified":"2018-01-04T12:57:52Z","published":"2018-01-04T12:57:52Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180019-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1026612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1068032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2633"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5715"}],"related":["CVE-2017-2633","CVE-2017-5715"],"summary":"Security update for kvm","upstream":["CVE-2017-2633","CVE-2017-5715"]}