[SUSE-SU-2018:1699-1] Security update for xen

Severity Important
Affected Packages 6
CVEs 4

Security update for xen

This update for xen fixes several issues.

This feature was added:

  • Added support for qemu monitor command

These security issues were fixed:

  • CVE-2018-3639: Prevent attackers with local user access from extracting information via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4 (bsc#1092631).
  • CVE-2017-5753,CVE-2017-5715,CVE-2017-5754: Improved Spectre v2 mitigations (bsc#1074562).

This non-security issue was fixed:

  • bsc#1086039 - Dom0 does not represent DomU cpu flags
ID
SUSE-SU-2018:1699-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2018/suse-su-20181699-1/
Published
2018-06-15T12:42:33
(6 years ago)
Modified
2018-06-15T12:42:33
(6 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/xen?arch=x86_64&distro=sles-12&sp=2 suse xen < 4.7.5_04-43.33.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools?arch=x86_64&distro=sles-12&sp=2 suse xen-tools < 4.7.5_04-43.33.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools-domU?arch=x86_64&distro=sles-12&sp=2 suse xen-tools-domU < 4.7.5_04-43.33.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs?arch=x86_64&distro=sles-12&sp=2 suse xen-libs < 4.7.5_04-43.33.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs-32bit?arch=x86_64&distro=sles-12&sp=2 suse xen-libs-32bit < 4.7.5_04-43.33.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-doc-html?arch=x86_64&distro=sles-12&sp=2 suse xen-doc-html < 4.7.5_04-43.33.1 sles-12 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...