[SUSE-SU-2018:2056-1] Security update for xen

Severity Moderate
Affected Packages 7
CVEs 5

Security update for xen

This update for xen fixes the following issues:

Security issues fixed:

  • CVE-2018-12617: Fix integer overflow that causes segmentation fault in qmp_guest_file_read() with g_malloc() (bsc#1098744).
  • CVE-2018-3665: Fix Lazy FP Save/Restore issue (XSA-267) (bsc#1095242).
  • CVE-2018-11806: Fix heap buffer overflow while reassembling fragmented datagrams (bsc#1096224).
  • CVE-2018-12891: Fix possible Denial of Service (DoS) via certain PV MMU operations that affect the entire host (XSA-264) (bsc#1097521).
  • CVE-2018-12893: Fix crash/Denial of Service (DoS) via safety check (XSA-265) (bsc#1097522).

Bug fixes:

  • bsc#1079730: Fix failed 'write' lock.
  • bsc#1027519: Add upstream patches from January.
ID
SUSE-SU-2018:2056-1
Severity
moderate
URL
https://www.suse.com/support/update/announcement/2018/suse-su-20182056-1/
Published
2018-07-25T09:01:09
(6 years ago)
Modified
2018-07-25T09:01:09
(6 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/xen?arch=x86_64&distro=sles-12 suse xen < 4.4.4_34-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools?arch=x86_64&distro=sles-12 suse xen-tools < 4.4.4_34-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools-domU?arch=x86_64&distro=sles-12 suse xen-tools-domU < 4.4.4_34-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs?arch=x86_64&distro=sles-12 suse xen-libs < 4.4.4_34-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs-32bit?arch=x86_64&distro=sles-12 suse xen-libs-32bit < 4.4.4_34-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-kmp-default?arch=x86_64&distro=sles-12 suse xen-kmp-default < 4.4.4_34_k3.12.61_52.136-22.71.2 sles-12 x86_64
Affected pkg:rpm/suse/xen-doc-html?arch=x86_64&distro=sles-12 suse xen-doc-html < 4.4.4_34-22.71.2 sles-12 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...