Описание
Security update for Xen
The Virtualization service XEN was updated to fix various bugs and security issues.
The following security issues have been fixed:
Security Issues:
Список пакетов
SUSE Linux Enterprise Server 11 SP1-LTSS
SUSE Linux Enterprise Server 11 SP1-TERADATA
Ссылки
- Link for SUSE-SU-2015:0745-1
- E-Mail link for SUSE-SU-2015:0745-1
- SUSE Security Ratings
- SUSE Bug 918995
- SUSE Bug 918998
- SUSE Bug 919464
- SUSE Bug 922705
- SUSE Bug 922706
- SUSE CVE CVE-2015-2044 page
- SUSE CVE CVE-2015-2045 page
- SUSE CVE CVE-2015-2151 page
- SUSE CVE CVE-2015-2756 page
Описание
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Затронутые продукты
Ссылки
- CVE-2015-2044
- SUSE Bug 918995
- SUSE Bug 918998
Описание
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2015-2045
- SUSE Bug 918998
Описание
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2015-2151
- SUSE Bug 918998
- SUSE Bug 919464
Описание
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Затронутые продукты
Ссылки
- CVE-2015-2756
- SUSE Bug 922706