[FEDORA-2018-1a467757ce] Fedora 27: xen

Severity Critical
Affected Packages 1
CVEs 26

preemption checks bypassed in x86 PV MM handling [XSA-264, CVE-2018-12891] x86:
#DB exception safety check can be triggered by a guest [XSA-265, CVE-2018-12893]
libxl fails to honour readonly flag on HVM emulated SCSI disks [XSA-266,
CVE-2018-12892] ---- Speculative register leakage from lazy FPU context
switching [XSA-267, CVE-2018-3665] fix for change in iasl output

Package Affected Version
pkg:rpm/fedora/xen?distro=fedora-27 < 4.9.2.6.fc27
ID
FEDORA-2018-1a467757ce
Severity
critical
Severity from
CVE-2018-12892
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2018-1a467757ce
Published
2018-07-13T16:38:02
(6 years ago)
Modified
2018-07-13T16:38:02
(6 years ago)
Rights
Copyright 2018 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1590984 Bug #1590984 - CVE-2018-12892 xsa-266 xen: libxl fails to honour readonly flag on HVM emulated SCSI disks https://bugzilla.redhat.com/show_bug.cgi?id=1590984
Bugzilla 1590985 Bug #1590985 - CVE-2018-12891 xen: preemption checks bypassed in x86 PV MM handling (XSA-264) https://bugzilla.redhat.com/show_bug.cgi?id=1590985
Bugzilla 1590979 Bug #1590979 - CVE-2018-12893 xen: x86 DB exception safety check can be triggered by a guest (XSA-265) https://bugzilla.redhat.com/show_bug.cgi?id=1590979
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/xen?distro=fedora-27 fedora xen < 4.9.2.6.fc27 fedora-27
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...