Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:0909-1

Опубликовано: 10 апр. 2018
Источник: suse-cvrf

Описание

Security update for xen

This update for xen fixes the following issues:

Update to Xen 4.7.5 bug fix only release (bsc#1027519)

Security issues fixed:

  • CVE-2018-7540: Fixed DoS via non-preemptable L3/L4 pagetable freeing (XSA-252) (bsc#1080635)

  • CVE-2018-7541: A grant table v2 -> v1 transition may crash Xen (XSA-255) (bsc#1080662)

  • CVE-2017-5753,CVE-2017-5715,CVE-2017-5754 Fixed information leaks via side effects of speculative execution (XSA-254). Includes Spectre v2 mitigation. (bsc#1074562)

  • Preserve xen-syms from xen-dbg.gz to allow processing vmcores with crash(1) (bsc#1087251)

  • Xen HVM: Fixed unchecked MSR access error (bsc#1072834)

  • Add script, udev rule and systemd service to watch for vcpu online/offline events in a HVM domU They are triggered via xl vcpu-set domU N (fate#324965)

  • Make sure tools and tools-domU require libs from the very same build

Список пакетов

SUSE Linux Enterprise Desktop 12 SP2
xen-4.7.5_02-43.27.1
xen-libs-4.7.5_02-43.27.1
xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2
xen-4.7.5_02-43.27.1
xen-doc-html-4.7.5_02-43.27.1
xen-libs-4.7.5_02-43.27.1
xen-libs-32bit-4.7.5_02-43.27.1
xen-tools-4.7.5_02-43.27.1
xen-tools-domU-4.7.5_02-43.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
xen-4.7.5_02-43.27.1
xen-doc-html-4.7.5_02-43.27.1
xen-libs-4.7.5_02-43.27.1
xen-libs-32bit-4.7.5_02-43.27.1
xen-tools-4.7.5_02-43.27.1
xen-tools-domU-4.7.5_02-43.27.1
SUSE Linux Enterprise Software Development Kit 12 SP2
xen-devel-4.7.5_02-43.27.1

Описание

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:xen-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2:xen-4.7.5_02-43.27.1

Ссылки

Описание

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:xen-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2:xen-4.7.5_02-43.27.1

Ссылки

Описание

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:xen-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2:xen-4.7.5_02-43.27.1

Ссылки

Описание

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:xen-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2:xen-4.7.5_02-43.27.1

Ссылки

Описание

An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:xen-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-32bit-4.7.5_02-43.27.1
SUSE Linux Enterprise Desktop 12 SP2:xen-libs-4.7.5_02-43.27.1
SUSE Linux Enterprise Server 12 SP2:xen-4.7.5_02-43.27.1

Ссылки
Уязвимость SUSE-SU-2018:0909-1