SUSE-SU-2021:0663-1

Source
https://www.suse.com/support/update/announcement/2021/suse-su-20210663-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0663-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2021:0663-1
Related
Published
2021-03-01T15:13:59Z
Modified
2021-03-01T15:13:59Z
Summary
Security update for open-iscsi
Details

This update for open-iscsi fixes the following issues:

Fixes for CVE-2019-17437, CVE-2020-17438, CVE-2020-13987 and CVE-2020-13988 (bsc#1179908):

  • check for TCP urgent pointer past end of frame
  • check for u8 overflow when processing TCP options
  • check for header length underflow during checksum calculation
References

Affected packages

SUSE:OpenStack Cloud 9 / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5 / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / open-iscsi

Package

Name
open-iscsi
Purl
pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.876-12.27.2

Ecosystem specific

{
    "binaries": [
        {
            "iscsiuio": "0.7.8.2-12.27.2",
            "libopeniscsiusr0_2_0": "2.0.876-12.27.2",
            "open-iscsi": "2.0.876-12.27.2"
        }
    ]
}