[SUSE-SU-2018:2081-1] Security update for xen

Severity Important
Affected Packages 6
CVEs 5

Security update for xen

This update for xen fixes the following issues:

Security issues fixed:

  • CVE-2018-12891: Fix preemption checks bypass in x86 PV MM handling (XSA-264) (bsc#1097521).
  • CVE-2018-12892: Fix libxl failure to honour readonly flag on HVM emulated SCSI disks (XSA-266) (bsc#1097523).
  • CVE-2018-12893: Fix #DB exception safety check that could be triggered by a guest (XSA-265) (bsc#1097522).
  • CVE-2018-11806: Fix heap buffer overflow while reassembling fragmented datagrams (bsc#1096224).
  • CVE-2018-3665: Fix lazy FP Save/Restore (XSA-267) (bsc#1095242).

Bug fixes:

  • bsc#1027519: Update to Xen 4.7.6 bug fix only release.
  • bsc#1087289: Xen BUG at sched_credit.c:1663.
  • bsc#1094725: virsh blockresize does not work with Xen qdisks.
ID
SUSE-SU-2018:2081-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2018/suse-su-20182081-1/
Published
2018-07-27T10:43:34
(6 years ago)
Modified
2018-07-27T10:43:34
(6 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/xen?arch=x86_64&distro=sles-12&sp=2 suse xen < 4.7.6_02-43.36.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools?arch=x86_64&distro=sles-12&sp=2 suse xen-tools < 4.7.6_02-43.36.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools-domU?arch=x86_64&distro=sles-12&sp=2 suse xen-tools-domU < 4.7.6_02-43.36.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs?arch=x86_64&distro=sles-12&sp=2 suse xen-libs < 4.7.6_02-43.36.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs-32bit?arch=x86_64&distro=sles-12&sp=2 suse xen-libs-32bit < 4.7.6_02-43.36.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-doc-html?arch=x86_64&distro=sles-12&sp=2 suse xen-doc-html < 4.7.6_02-43.36.1 sles-12 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...