[SUSE-SU-2022:3728-1] Security update for xen

Severity Important
Affected Packages 6
CVEs 7

Security update for xen

This update for xen fixes the following issues:

  • CVE-2022-26365: Fixed issue where Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (bsc#1200762).
  • CVE-2022-33740: Fixed issue where Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (bsc#1200762).
  • CVE-2022-33741: Fixed issue where data residing in the same 4K page as data shared with a backend was being accessible by such backend (bsc#1200762).
  • CVE-2022-33742: Fixed issue where data residing in the same 4K page as data shared with a backend was being accessible by such backend (bsc#1200762).
  • CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806).
  • CVE-2021-28689: Fixed speculative vulnerabilities with bare (non-shim) 32-bit PV guests (bsc#1185104).
  • CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807).
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/xen?arch=x86_64&distro=sles-12&sp=5 suse xen < 4.12.4_28-3.77.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools?arch=x86_64&distro=sles-12&sp=5 suse xen-tools < 4.12.4_28-3.77.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-tools-domU?arch=x86_64&distro=sles-12&sp=5 suse xen-tools-domU < 4.12.4_28-3.77.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs?arch=x86_64&distro=sles-12&sp=5 suse xen-libs < 4.12.4_28-3.77.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-libs-32bit?arch=x86_64&distro=sles-12&sp=5 suse xen-libs-32bit < 4.12.4_28-3.77.1 sles-12 x86_64
Affected pkg:rpm/suse/xen-doc-html?arch=x86_64&distro=sles-12&sp=5 suse xen-doc-html < 4.12.4_28-3.77.1 sles-12 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...